Which of the following tools can be used for passive OS fingerprinting?
A.
nmap
B.
ping
C.
tcpdump
D.
tracert
The Answer Is:
C
This question includes an explanation.
Explanation:
The correct answer is C, tcpdump. Passive OS fingerprinting identifies the operating system of a target by observing and analyzing network traffic without actively sending probe packets to the target system. Tools such as tcpdump capture packets traversing a network and allow analysts to inspect characteristics like TCP window size, Time-To-Live (TTL) values, TCP options, and packet behavior that can reveal the operating system in use. Because the target is not directly interrogated, passive fingerprinting is stealthier and less likely to trigger alerts.
Nmap is primarily associated with active OS fingerprinting because it sends specially crafted packets and analyzes the responses to determine the target operating system. Ping is used mainly to verify host availability, while tracert (traceroute) identifies network paths and intermediate hops between systems. Neither ping nor tracert performs OS fingerprinting.
In CEH reconnaissance and enumeration topics, passive information gathering focuses on observing existing communications rather than generating new traffic. Therefore, among the given options, tcpdump is the most appropriate tool for passive OS fingerprinting because it captures and analyzes network traffic without directly probing the target.
312-50v13 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"