Question 1
Which option would you use to perform a UDP scan?
Correct Answer:
-sU
Explanation:
UDP scanning probes UDP ports because UDP is a connectionless protocol with no handshake. When you use the UDP scan switch, Nmap sends UDP packets to target ports and waits for responses. If a port replies with a UDP payload, it’s likely open. If you receive an ICMP Port Unreachable message, the port is closed. If there is no reply, the port is usually considered open|filtered, since a firewall or filtering device might be dropping the packets. This approach tends to be slower and noisier than TCP scans, and many hosts filter or rate-limit UDP traffic. Other common scanning methods target TCP behavior: one uses a SYN packet to elicit a half-open handshake, another attempts a full TCP connect, and another analyzes responses to ACK probes to infer firewall rules. The UDP switch is the appropriate choice when you specifically need to assess UDP ports.
Question 2
What is the purpose of the -sA option and what does an ACK scan reveal about firewall behavior?
Correct Answer:
It performs a TCP ACK scan to map firewall rules; It reveals stateless vs stateful filtering and doesn’t indicate open ports.
Explanation:
The main idea here is how an ACK scan works and what it can reveal about a firewall. The -sA option performs a TCP ACK scan, sending ACK packets to each port. Because ACKs aren’t used to open a connection, the target’s responses (or lack thereof) depend on the firewall’s rules rather than on whether a port is actually open. If a firewall is stateful, it tends to filter unsolicited ACKs and may drop them, producing no response for filtered ports; if a firewall is stateless, you’ll see different, predictable responses for allowed versus blocked paths. By observing which ports elicit a RST or no response, you can map the firewall’s rule set and determine whether filtering is stateful or stateless. This doesn’t indicate open ports, which is why this scan is specifically about firewall behavior rather than port openness.
Question 3
What does the --reason option do and why would you enable it?
Correct Answer:
--reason prints the reason a port is in its stated state; helps interpret results, especially when states are ambiguous.
Explanation:
The option is about showing why Nmap classified a port in a particular state. Enabling it adds a reason for each port’s state, so you can see the underlying cause—like a firewall filter or a specific type of response—that led to labels such as open, closed, or open|filtered. This makes results much easier to interpret, especially when the state is ambiguous or influenced by intermediate devices. It’s not about kinematics, filtering by reason codes, or simply increasing verbosity, which is why those other ideas don’t fit.
Question 4
Which statement best describes idle scans in Nmap?
Correct Answer:
They rely on a zombie host and IPID timing and are often less reliable.
Explanation:
Idle scans rely on a zombie host and IPID timing to infer the target’s port state, offering a covert probing method rather than directly from the scanner. The zombie is used to generate traffic toward the target, with the scan manipulating IP spoofing so the target’s responses appear to come from the zombie. By watching how the zombie’s IPID—the identification value in IP headers—changes between probes, Nmap can deduce whether the target port is open or closed based on the observed timing patterns. This approach is appealing for stealth, since the true source appears to be the zombie, but it’s often less reliable because it hinges on the zombie’s IPID behavior being predictable. Some operating systems randomize IPID or behave inconsistently under load, and network factors like NAT, firewalls, packet loss, or traffic elsewhere on the path can disrupt the timing measurements, leading to unclear results or failures to detect states accurately.
Question 5
How do you scan a specific port range in Nmap, for example ports 80, 443, and 1024-1050?
Correct Answer:
-p 80,443,1024-1050.
Explanation:
In Nmap, the -p option controls which ports are scanned. You can mix individual ports with port ranges by listing them separated with commas. For your target of ports 80, 443, and the range 1024-1050, the correct syntax is -p 80,443,1024-1050. This exactly specifies the two single ports plus the block from 1024 through 1050. This works because -p accepts a comma-separated list of ports and ranges, and the range 1024-1050 includes every port from 1024 to 1050 inclusive. Using a range like 80-443 would scan every port between 80 and 443, which isn’t the same as scanning only 80 and 443. And using spaces or a non-existent flag like -ports would not be parsed correctly by Nmap.
Question 1
Exam overview

About this Exam

Prepare with the Nmap ZenMap Switches Practice Test practice quiz. This question bank includes 10 questions covering scan, nmap, describes, port, and intrusive. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

Nmap ZenMap Switches Practice Test

This practice set contains 10 questions from the matching question bank and focuses on scan, nmap, describes, port, and intrusive. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.