CompTIA CySA+ (CS0-003)Security OperationsHard

While reviewing a packet capture, an analyst determines the likely operating system of a remote host solely by examining the initial TTL value (128) and TCP window size in response packets that were already captured passively on the network, without sending any probe packets to the host. Which technique is being used?

  1. AService enumeration
  2. BPassive OS fingerprinting
  3. CBanner grabbing
  4. DActive OS fingerprinting
Show answer & explanation

Correct answer: B. Passive OS fingerprinting

Passive OS fingerprinting infers the operating system by analyzing characteristics of traffic that was already observed (such as initial TTL and TCP window size), without sending any crafted probes to the target. Active fingerprinting (e.g., nmap -O) sends specially crafted packets and analyzes responses, banner grabbing reads service version strings from application responses, and service enumeration identifies open ports/services rather than the OS.

Why the other options are wrong

  • A. Service enumeration identifies open ports and running services, not the OS via TTL.
  • C. Banner grabbing reads service/version strings, not TTL/window size values.
  • D. Active fingerprinting requires sending probe packets, which did not occur here.

Passive OS Fingerprinting

A technique for identifying a remote host's operating system by analyzing characteristics of naturally occurring traffic (TTL, TCP window size, options) without sending any probe packets.

  • Common initial TTLs: 64 (Linux/Unix), 128 (Windows), 255 (Cisco/network devices)
  • No packets sent to target, reducing detection risk
  • Contrasts with active fingerprinting (e.g., nmap -O) which crafts probe packets

Memory trick: 'Passive listens quietly; active knocks on the door.'

More Security Operations questions