ITPEC FE Subject A October 2025 Question 32
ITPEC FE Subject A October 2025 — Question 32 of 60
Port scanning — identifies open ports and running services during the reconnaissance phase of an attack.
Port scanning is a preliminary investigation technique. The attacker sends probes to various ports on a target system to discover which services are listening and potentially vulnerable. This happens before any actual exploitation.
Why not others:
- (a) Post-processing is about covering tracks after the attack — port scanning happens before
- (c) Privilege escalation is after gaining initial access — scanning for accounts to escalate is a later stage
- (d) Unauthorized action (data exfiltration) is the final stage — port scanning precedes any access
Key rule: Port scanning = reconnaissance = preliminary investigation stage, always happens first.
AI-generated — may contain errors
The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.
This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official FE past-paper collection or Report an issue.