CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium
A penetration tester is conducting reconnaissance against a target organization's network perimeter. They perform an Nmap scan with the '-sS' and '-T4' flags against a range of public IP addresses. However, many ports are reported as 'filtered'. Which of the following is the most likely reason for this result?
- AThe Nmap scanner is not properly configured to handle fragmented packets.
- BAn intrusion detection system (IDS) is blocking the Nmap probes.
- CA stateful firewall is blocking the initial SYN packets from the scanner.
- DThe target's firewall is dropping the SYN-ACK packets from the Nmap scanner.
Show answer & explanationAnswer & explanation
Correct answer: C. A stateful firewall is blocking the initial SYN packets from the scanner.
A 'filtered' state in Nmap's SYN scan ('-sS') typically indicates that a stateful firewall is present and is dropping the initial SYN packets sent by Nmap, preventing them from reaching the target host and thus not receiving any response.
Why the other options are wrong
- A. Fragmented packets are not directly related to 'filtered' status in this context and Nmap handles them well.
- B. An IDS might alert, but a 'filtered' status usually points to a firewall actively blocking.
- D. If SYN-ACKs were dropped, the state would likely be 'open|filtered' or 'closed|filtered', as Nmap would still send the initial SYN.
Nmap 'filtered' port state
When Nmap reports a port as 'filtered', it means that a firewall, filter, or other network device is blocking the probe, preventing Nmap from determining if the port is open or closed.
- Indicates a firewall or filter is present.
- Nmap cannot determine the port's true state (open/closed).
- Often seen when initial SYN packets are dropped by a stateful firewall.
Memory trick: Nmap's signals show the port's mood.