During a ping sweep to identify live hosts, you receive responses from only Unix-like systems. Which statement is most accurate?

Enhance your knowledge as a Computer Hacking Forensic Investigator with the CHFI v11 Test. Use flashcards and multiple-choice questions, complete with hints and detailed explanations, to prepare effectively and ace your exam!

Multiple Choice

During a ping sweep to identify live hosts, you receive responses from only Unix-like systems. Which statement is most accurate?

Explanation:
A ping sweep sends ICMP Echo Requests to a range of addresses to see which hosts answer with ICMP Echo Replies. If you’re getting responses only from Unix-like systems, that means those hosts are replying to the ICMP echo while many Windows hosts are not replying—likely because their ICMP Echo responses are blocked by firewall rules or security policies. In this context, the observation is best described by saying that only Unix and Unix-like systems will reply to this scan, since they typically have ICMP echo responses enabled and reachable in this environment. The other statements don’t align with what you observed: Windows hosts are not the ones replying here; the behavior isn’t about switching hardware blocking broadcast addresses in general, and IBM AS/400 is not the sole or likely source of replies in this scenario.

A ping sweep sends ICMP Echo Requests to a range of addresses to see which hosts answer with ICMP Echo Replies. If you’re getting responses only from Unix-like systems, that means those hosts are replying to the ICMP echo while many Windows hosts are not replying—likely because their ICMP Echo responses are blocked by firewall rules or security policies. In this context, the observation is best described by saying that only Unix and Unix-like systems will reply to this scan, since they typically have ICMP echo responses enabled and reachable in this environment.

The other statements don’t align with what you observed: Windows hosts are not the ones replying here; the behavior isn’t about switching hardware blocking broadcast addresses in general, and IBM AS/400 is not the sole or likely source of replies in this scenario.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy