Which option makes scans originate from spoofed IP addresses?

Study for the Nmap/ZenMap Switches Test. Prepare with flashcards and multiple choice questions, each question provides hints and explanations. Get ready for your exam!

Multiple Choice

Which option makes scans originate from spoofed IP addresses?

Explanation:
Decoy scanning is about making the scan appear as if it comes from multiple IP addresses. The decoy option enables this by letting you specify one or more decoy IPs (or request random decoys). Nmap then uses those addresses as the source for some packets, so the target sees traffic from several origins. This directly implements spoofed-origin behavior and is used to confuse IDS and log analysis. The other options don’t modify where the scan appears to originate. OS detection changes how the target is identified, not the source of the packets. Aggressive mode combines several checks, including version and OS detection, but still originates from your IP. Fast mode speeds up scanning by checking fewer ports, without spoofing the source.

Decoy scanning is about making the scan appear as if it comes from multiple IP addresses. The decoy option enables this by letting you specify one or more decoy IPs (or request random decoys). Nmap then uses those addresses as the source for some packets, so the target sees traffic from several origins. This directly implements spoofed-origin behavior and is used to confuse IDS and log analysis.

The other options don’t modify where the scan appears to originate. OS detection changes how the target is identified, not the source of the packets. Aggressive mode combines several checks, including version and OS detection, but still originates from your IP. Fast mode speeds up scanning by checking fewer ports, without spoofing the source.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy