Case EBA578 · Network · L2 Practitioner
Port Scanning Techniques
Practise as: Explain it
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- TCP SYN scan (nmap -sS) sends SYN, reads SYN/ACK (open) or RST (closed), never completes the handshake
- Connect scan (-sT) completes the handshake and is logged by apps; UDP scan (-sU) is slow and ambiguous
- TCP: no response or ICMP unreachable usually means filtered; UDP: ICMP port unreachable means closed, silence is open|filtered
- Service/version detection (-sV) and OS fingerprinting use banner and TCP/IP stack quirks
- Detect via many ports from one source in a short window; masscan and slow scans evade naive thresholds
If the interviewer pushes back
- How does an idle (zombie) scan hide the true source of a scan?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.