Which of the following is an indicator that port scanning is being performed?

Study for the Wireshark Block 5 Exam. Prepare with flashcards and multiple choice questions, each offering hints and explanations. Ace your exam with the best resources!

Multiple Choice

Which of the following is an indicator that port scanning is being performed?

Explanation:
Port scanning shows up when a single source sends probes to many ports across multiple destinations in a short period. This pattern—a flood of TCP SYNs aimed at a broad range of ports on many hosts—signals an attempt to discover which ports are open or filtered without fully establishing connections. The goal is to map services available on multiple targets, so the traffic is spread across ports and destinations rather than concentrated on normal, legitimate connections. This differs from other activities: a large number of DNS responses points to DNS-related traffic, not port probing; many ICMP echo replies indicate a ping-based discovery or a network reachability check; repeated NAT translations reflect translation activity rather than probing ports.

Port scanning shows up when a single source sends probes to many ports across multiple destinations in a short period. This pattern—a flood of TCP SYNs aimed at a broad range of ports on many hosts—signals an attempt to discover which ports are open or filtered without fully establishing connections. The goal is to map services available on multiple targets, so the traffic is spread across ports and destinations rather than concentrated on normal, legitimate connections.

This differs from other activities: a large number of DNS responses points to DNS-related traffic, not port probing; many ICMP echo replies indicate a ping-based discovery or a network reachability check; repeated NAT translations reflect translation activity rather than probing ports.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy