サンフランシスコでのセキュリティ評価において、倫理的なハッカーは、ステルス的な偵察行為に対するネットワークの耐性を評価するという任務を負っています。ハッカーは、侵入検知システムによる検知を回避するためにTCPフラグを活用したスキャン手法を用いる必要があります。標的の応答挙動からポート状態を推測し、完全な接続を確立することなく、この戦略に最も適したアプローチはどれでしょうか?
正解:C
A FIN scan is a classic "stealth" TCP scan technique discussed in CEH network scanning methodology.
Unlike a TCP Connect scan, which completes the full three-way handshake and is highly visible in logs, a FIN scan sends a TCP packet with only the FIN flag set to a target port. The scan then interprets the target's response to infer whether the port is open or closed, without establishing a normal TCP session. This matches the scenario's requirement to "infer port states without completing a full connection" and to keep visibility low.
The logic relies on expected TCP behavior defined for many TCP/IP stacks. For a closed port, the target typically responds with an RST packet, indicating there is no service listening. For an open port, many systems do not respond at all to an unexpected FIN packet (because it does not correspond to an existing connection). That "no response" behavior becomes the signal the tester uses to suspect the port may be open or filtered. CEH emphasizes that because FIN scans do not perform a handshake, they can be less likely to trigger certain basic connection-based logging, and they generate fewer obvious connection events than TCP Connect scans.
Option D, NULL scan, is also a stealth method, but it uses a packet with no flags set. The question specifically highlights leveraging TCP flags and is commonly mapped in CEH-style questions to FIN scanning as the representative "TCP flag stealth scan." Option B is too generic, and option A is the most detectable. Therefore, FIN scan best aligns with the described stealth reconnaissance strategy.