EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesHard

A penetration tester is attempting to map the network topology of a target organization. They are using traceroute to determine the path packets take to reach various hosts. However, some routers along the path are configured to drop ICMP Time Exceeded messages, which are crucial for traceroute's operation. Which of the following Nmap options could the tester use to perform a similar route tracing function by sending TCP SYN or ACK packets instead of ICMP?

  1. A-sU
  2. B-sS
  3. C-PE
  4. D--traceroute
Show answer & explanation

Correct answer: D. --traceroute

The Nmap '--traceroute' option can perform route tracing using various protocols, including TCP SYN, ACK, or UDP, in addition to ICMP. When ICMP Time Exceeded messages are blocked, Nmap can adapt by sending TCP or UDP probes, making it effective for mapping network paths where standard ICMP traceroute fails.

Why the other options are wrong

  • A. -sU is a UDP scan for open ports, not a traceroute function.
  • B. -sS is a TCP SYN scan for open ports, not a traceroute function.
  • C. -PE is for ICMP echo ping, which is exactly what's being blocked and is not a traceroute option.

Nmap Traceroute (--traceroute)

An Nmap option that performs route tracing to a target host, similar to the traditional traceroute utility. It can use various protocols (ICMP, TCP SYN/ACK, UDP) to determine the path, making it more flexible in environments where ICMP is blocked.

  • Maps network path to target.
  • Can use ICMP, TCP, or UDP probes.
  • Useful when ICMP is filtered.
  • Reveals intermediate hops and latency.

Memory trick: Traceroute maps the trail, even if ICMP fails.

More Reconnaissance Techniques questions