EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesMedium

An ethical hacker is performing a black-box penetration test. They need to identify open ports and services on a target network without triggering intrusion detection systems (IDS) that are highly sensitive to full TCP handshakes. Which Nmap scan type is most suitable for this objective?

  1. AXmas Scan (-sX)
  2. BSYN Stealth Scan (-sS)
  3. CTCP Connect Scan (-sT)
  4. DUDP Scan (-sU)
Show answer & explanation

Correct answer: B. SYN Stealth Scan (-sS)

The SYN Stealth Scan (-sS) is designed to be stealthy by not completing the full TCP 3-way handshake. It sends a SYN packet and if a SYN/ACK is received, it sends an RST, preventing the target from logging a full connection, which makes it less likely to be detected by IDS.

Why the other options are wrong

  • A. Xmas Scan can be stealthy, but it's often used to determine port states (open/closed/filtered) by manipulating TCP flags, and not specifically for avoiding full TCP handshakes like the SYN scan.
  • C. TCP Connect Scan completes the full TCP 3-way handshake and is easily detectable by IDS.
  • D. UDP Scan is for UDP ports, not for avoiding TCP handshake detection, and can be slow/unreliable for open port detection.

SYN Stealth Scan (-sS)

An Nmap scan technique that sends a SYN packet and, upon receiving a SYN/ACK, immediately sends an RST packet to avoid completing the TCP handshake, making it less detectable.

  • Does not complete TCP 3-way handshake
  • Less likely to be logged by target systems
  • Requires raw packet privileges

Memory trick: SYN is stealthy because it doesn't say 'hello' all the way.

More Reconnaissance Techniques questions