CompTIA PenTest+ (PT0-003) flashcards
192 free flashcards. Tap a card to flip it.
Compliance-Based Assessment
Flip cardA penetration test driven primarily by the need to satisfy a regulatory or contractual framework's specific checklist of required controls.
- Common drivers include HIPAA, PCI DSS, and SOX
- Scope is often narrower and checklist-driven
- Contrasts with goals-based or objective-driven testing
Memory trick: Compliance = Checklist; Goals = Get the flag
Shared Library Injection for Persistence
Flip cardA stealthy persistence technique where a malicious shared library (e.g., .so on Linux, .dll on Windows) is injected into a legitimate process, allowing the attacker to execute code within the context of that process.
- Can be triggered by specific events or function calls within the legitimate process.
- Harder to detect than file-based backdoors or user modifications.
- Requires root privileges to modify system libraries or linker configurations.
Memory trick: Shared libraries hide in plain sight.
DNS Tunneling for C2/Exfiltration
Flip cardA covert communication technique that encodes data within DNS queries and responses to create a C2 channel or exfiltrate data, often bypassing firewalls that restrict other outbound traffic.
- Leverages the fact that DNS traffic is almost universally allowed outbound.
- Tools like iodine and dnscat2 facilitate DNS tunneling.
- Can be slow due to the nature of DNS protocol and query limits.
Memory trick: DNS hides secrets in plain sight.
Nmap Fast Scan (-F)
Flip cardThe Nmap `-F` (fast scan) option scans only the 100 most common ports, significantly reducing scan time and network traffic compared to scanning all 65535 ports.
- Scans 100 most common ports
- Reduces scan time and network traffic
- Useful for quick, less intrusive reconnaissance
Memory trick: Nmap's Fast Scan is a Quick Way to Find Public Services.
Data Handling/Destruction Clause
Flip cardA contractual provision requiring the testing firm to securely retain and eventually destroy client data, including credentials and hashes, within a specified timeframe after the engagement.
- Usually located in the MSA or SOW
- Covers cracked hashes, captured credentials, and scan data
- Protects the client from long-term exposure of sensitive artifacts
Memory trick: Deliver, Destroy, reDo (retest), Done: the four D's after the report.
DNS Zone Transfer (AXFR)
Flip cardA mechanism used to replicate DNS database files (zone files) from a primary DNS server to secondary DNS servers. If misconfigured, it can be exploited to obtain a complete list of a domain's DNS records, including internal hosts.
- Uses the 'AXFR' (Asynchronous Full Zone Transfer) query type.
- Should typically be restricted to authorized secondary DNS servers.
- A successful transfer reveals all DNS records for a domain.
- The 'dig' utility is commonly used to perform this.
Memory trick: DNS queries unveil network names.
CVSS Privileges Required (PR)
Flip cardA CVSS v3.1 base metric indicating the level of access an attacker must have before exploiting a vulnerability: None, Low, or High.
- PR:N = no privileges needed (higher risk)
- PR:L = basic user-level privileges needed
- PR:H = admin-level privileges needed (lower practical risk)
Memory trick: PR checks the 'Pass' you need at the door before you can attack
Subdomain Takeover
Flip cardA vulnerability where a DNS record points to a deprovisioned or unclaimed third-party/cloud resource, allowing an attacker to claim that resource and control the subdomain.
- Common with CNAMEs pointing to cloud services (Azure, AWS, GitHub Pages)
- Tools like Sublist3r and dnsrecon help identify dangling records
- Fix involves removing the stale DNS entry or reclaiming the resource
Memory trick: 'Dangling CNAME Dangles Danger'
Hashcat Mask Attack Syntax
Flip cardA hashcat mask attack (mode 3) defines a per-position character set using placeholders like ?l, ?u, ?d, and ?s to model known password structures.
- ?l = lowercase letter, ?u = uppercase letter
- ?d = digit, ?s = special character
- Masks dramatically reduce keyspace when password structure is known
Memory trick: Build the mask like spelling the password's DNA, position by position
PTES Threat Modeling
Flip cardThe PTES phase where testers identify threat communities, map them to business assets, and determine realistic attack scenarios before technical testing begins.
- Uses output from Intelligence Gathering
- Maps threat agents to specific assets
- Produces attack scenarios that guide Vulnerability Analysis and Exploitation
Memory trick: Pirates Intelligently Threaten Villagers, Exploiting, Plundering, Reporting
VLAN Hopping - Double Tagging
Flip cardA Layer 2 attack where an attacker sends frames with two nested 802.1Q VLAN tags so the switch strips the outer native VLAN tag and forwards the inner-tagged frame into another VLAN.
- Exploits native VLAN untagged forwarding behavior
- One-way attack (no return traffic path)
- Mitigated by not using VLAN 1 as native VLAN and tagging native VLAN traffic
Memory trick: 'Two tags, one strip, sneak into the next VLAN' — double tagging
Burp Suite Passive Scanning
Flip cardA Burp Scanner mode that inspects traffic already captured by the proxy to flag potential vulnerabilities without sending new requests to the target.
- Lower risk than active scanning
- Detects issues like missing security headers, information leakage
- Often used first before running an active scan
Memory trick: Crawl first, then Peek quietly (passive) before Poking (active)
Hashcat NTLM Dictionary Attack
Flip cardUsing the 'hashcat' tool to crack NTLM password hashes by comparing them against a list of words or phrases from a dictionary file.
- Requires 'hashcat -m 1000' for NTLM hash type.
- Uses '-a 0' for straight/dictionary attack mode.
- Input files are the hash list and the wordlist.
Memory trick: Hashcat hammers keys; remember the mode and attack type.
db_nmap
Flip cardA Metasploit Framework console command that runs Nmap and automatically imports the scan results into the active project database.
- Requires an active database connection (db_status)
- Results can be viewed later with 'hosts' and 'services'
- Streamlines recon-to-exploitation workflow
Memory trick: 'Database Never Manually Imports' — db_nmap does it live
Nmap Version Detection (-sV)
Flip cardAn Nmap option that probes open ports with protocol-specific probes to identify the running service and its version number.
- Used after discovering open ports to enrich findings
- Often combined with -sS or -sT scans
- Results feed directly into vulnerability/CVE correlation
Memory trick: 'V' for Version — Nmap's Voice ID for services
Boolean-based Blind SQL Injection
Flip cardA type of SQL injection where the attacker sends SQL queries that force the application to return a different result depending on whether a true or false condition is met, without directly returning database errors or data.
- Relies on observable changes in application behavior (e.g., page content, login success).
- Typically uses logical operators like `AND` or `OR` with a true/false condition.
- Often used when error messages or direct data retrieval are suppressed.
Memory trick: Blind injections guess, union joins, and errors expose.
Nikto
Flip cardAn open-source web server scanner that checks for outdated software, dangerous files, and common misconfigurations.
- Command-line tool, often paired with Nmap results
- Checks thousands of known vulnerable files/CGIs
- Generates a lot of noise, not stealthy
Memory trick: 'Nikto Knocks on Web Doors' first
Captive Portal Bypass
Flip cardTechniques used to circumvent the authentication requirements of a captive portal, which typically restricts internet access until users agree to terms or provide credentials.
- Captive portals usually track users by MAC address.
- Spoofing an authenticated MAC address is a common bypass.
- Other methods include DNS manipulation or exploiting portal vulnerabilities.
Memory trick: Wireless world: Evil twins, DNS tricks, MAC magic, WPS woes.
Third-Party Cloud Testing Authorization
Flip cardThe requirement to obtain separate approval from a cloud service provider before conducting penetration tests on infrastructure they host, in addition to client authorization.
- Cloud providers (AWS, Azure, GCP) have specific testing policies
- Failure to comply can violate provider ToS and cause legal issues
- Client's SOW/RoE alone does not authorize testing of third-party infrastructure
Memory trick: Cloud = someone else's server, so ask them too!
Nmap 'filtered' port state
Flip cardWhen Nmap reports a port as 'filtered', it means that a firewall, filter, or other network device is blocking the probe, preventing Nmap from determining if the port is open or closed.
- Indicates a firewall or filter is present.
- Nmap cannot determine the port's true state (open/closed).
- Often seen when initial SYN packets are dropped by a stateful firewall.
Memory trick: Nmap's signals show the port's mood.
Web Shell Injection (Deep)
Flip cardA stealthy web shell deployment technique where malicious code is embedded directly into an existing, legitimate application file on the web server, rather than uploading a new, standalone web shell file.
- Bypasses file integrity monitoring (FIM) that checks for new files.
- Requires careful blending of malicious code with legitimate code to avoid detection.
- Can be harder to detect via signature-based antivirus if obfuscated.
Memory trick: Inject into existing code, hide in plain sight.
Metasploit Exploit Modules
Flip cardMetasploit Framework modules designed to take advantage of specific vulnerabilities in target systems to gain unauthorized access or execute code.
- Categorized by target OS and service (e.g., windows/smb).
- Used for initial access and privilege escalation.
- Often paired with payloads to define post-exploitation actions.
Memory trick: Exploits attack, auxiliaries assist, payloads perform, and posts process.
Username Enumeration
Flip cardA vulnerability where an attacker can determine valid usernames from an application's response, typically by observing different error messages or response times for valid versus invalid usernames.
- Applications should return generic error messages for both invalid username and password.
- Can be exploited to create targeted password spraying lists.
- Often detected by observing HTTP response codes, body content, or timing differences.
Memory trick: Usernames are keys to the kingdom; enumerate them wisely.
Mimikatz for Credential Extraction
Flip cardA post-exploitation tool primarily used to extract credentials (plaintext passwords, hashes, Kerberos tickets) from memory on Windows systems, crucial for lateral movement.
- Integrated into Metasploit's Meterpreter as a post-exploitation module.
- Targets the Local Security Authority Subsystem Service (LSASS) process.
- Requires elevated privileges (e.g., SYSTEM) to function effectively.
Memory trick: Mimikatz extracts keys from memory's maze.
Bluesnarfing
Flip cardA Bluetooth attack that steals data such as contacts, calendar entries, and messages from a target device by exploiting insecure Bluetooth services like OBEX Push.
- Requires the device to be discoverable/pairable and vulnerable
- Distinct from bluejacking (sends data) and bluebugging (full device control)
- Mitigated by disabling Bluetooth discoverability when not in use
Memory trick: Snarf = to steal food quietly; bluesnarfing quietly steals your data
Burp Intruder Sniper Attack
Flip cardAn Intruder attack type that uses a single payload set and inserts each payload into one defined position at a time, making it suitable for testing a single parameter.
- One payload set, one position at a time.
- Efficient for testing single parameters.
- Commonly used for IDOR, SQL injection, or XSS on a single input.
Memory trick: Sniper targets one spot, Battering Ram hits everywhere at once.
Nmap OS Detection
Flip cardNmap's capability to identify the operating system running on a target host by analyzing various network responses.
- Uses TCP/IP fingerprinting.
- Requires at least one open and one closed TCP port for accuracy.
- Can be performed with the `-O` flag.
Memory trick: Nmap reveals hidden hosts and their digital identities.
Post-Exploitation Cleanup
Flip cardThe process of removing all traces of a penetration test or compromise from a system, including logs, temporary files, created accounts, and deployed tools.
- Crucial for avoiding detection and maintaining stealth.
- Involves clearing command histories, system logs, and temporary directories.
- Also includes removing any persistence mechanisms or backdoors.
Memory trick: To clean Linux, sweep the logs, history, and temp, but not the core bins.
Nmap Scanning via SOCKS Proxy
Flip cardUsing 'nmap' to scan target networks that are not directly reachable from the attacker's machine by routing 'nmap' traffic through a SOCKS proxy established on a compromised host.
- Requires a SOCKS proxy to be active on the compromised host.
- Uses the '--proxy' option in 'nmap' to specify the proxy server.
- Enables network discovery and vulnerability scanning in segmented environments.
Memory trick: Nmap can weave through networks using a proxy thread.
Report Structure (Executive Summary + Technical Detail)
Flip cardA penetration test report format that separates business-risk-focused content for executives from detailed technical findings for remediation teams.
- Executive summary translates risk into business terms
- Technical section includes reproduction steps and evidence
- Serves dual audiences with different needs
Memory trick: Top for the boss, bottom for the techs
Hidden Windows Local User
Flip cardA persistence technique involving the creation of a new local user account that is then hidden from standard Windows user enumeration interfaces (e.g., login screen, Control Panel), making it less likely to be discovered.
- Often achieved by modifying registry keys (e.g., `HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\Names`).
- Requires administrator privileges to create and hide the account.
- Meterpreter's `hide_user` module automates this process.
Memory trick: Hidden users keep access unseen.
Nmap ACK Scan (-sA)
Flip cardAn Nmap scan type that sends only an ACK packet to the target port. It is used to determine if a port is 'filtered' by a firewall or 'unfiltered' (open or closed), without attempting to establish a full connection.
- Does not determine if a port is open, only if it's filtered or unfiltered.
- Useful for mapping firewall rules and identifying stateful firewalls.
- A non-filtered port will respond with an RST; a filtered port will drop the packet or send ICMP error.
Memory trick: ACK scans ACK-nowledge the firewall's presence.
Business Email Compromise (BEC)
Flip cardA social engineering attack in which an attacker compromises or spoofs a trusted business email account to trick an organization into making fraudulent wire transfers or disclosing sensitive information.
- Often targets accounts payable/finance staff via vendor or executive impersonation
- Relies on existing trust relationships and plausible context (invoices, urgency)
- Mitigated by out-of-band payment verification and email authentication (DMARC/SPF/DKIM)
Memory trick: BEC = a wolf wearing the vendor's email suit to steal the payroll
False Positive
Flip cardA scan result indicating a vulnerability exists when it actually does not, often due to unreliable version/banner-based detection.
- Common cause: banner grabbing without verifying actual patch level
- Manual validation/exploitation confirms or disproves findings
- Credentialed scans reduce false positive rates
Memory trick: TP=真, FP=Fake alarm, FN=Missed danger, TN=真 clear
LLMNR/NBT-NS Poisoning
Flip cardA network attack that exploits vulnerabilities in Link-Local Multicast Name Resolution (LLMNR) and NetBIOS Name Service (NBT-NS) protocols to intercept name resolution requests and trick clients into authenticating to an attacker-controlled server, thereby capturing NTLM hashes.
- Works by responding to broadcast name resolution queries.
- Effective for capturing NTLMv2 hashes.
- Can be performed across network segments if broadcasts are routed or attacker has presence.
- Tools like Responder and Inveigh are commonly used.
Memory trick: LLMNR/NBT-NS poisoning: Broadcasts betray, hashes convey.
Passive DNS Enumeration
Flip cardGathering DNS information about a target without direct interaction, relying on publicly available data from third-party sources.
- Uses search engines, public archives, and OSINT tools.
- Minimizes detection risk.
- Examples: Google dorking, querying VirusTotal, Shodan.
Memory trick: DNS: Passive, Active, Zone, Brute.
SSH Tunneling for Pivoting
Flip cardA technique where an SSH connection is used to create an encrypted tunnel, allowing network traffic to be forwarded between hosts that are not directly reachable.
- Bypasses firewall restrictions by relaying traffic through a compromised host.
- Can be used for port forwarding (local, remote, dynamic).
- Requires SSH access to at least one intermediary host.
Memory trick: To move laterally, sometimes you need to pivot and reroute.
WPA2 Handshake Capture
Flip cardAn attacker captures the WPA2 four-way handshake between client and AP, often forcing reauthentication via a deauthentication attack to speed up capture.
- Deauth frames force client disconnect/reconnect
- Handshake captured with airodump-ng
- Cracked offline with hashcat mode 22000 or aircrack-ng
Memory trick: 'Deauth to force the handshake to happen again'
Windows Command Line Host Discovery
Flip cardLeveraging native Windows commands like 'ping' and 'for' loops to discover active hosts on a local network segment without installing third-party tools.
- Utilizes 'ping' for ICMP echo requests.
- 'for' loops enable iterating through IP ranges.
- 'findstr' can filter output for successful replies.
- Useful for internal reconnaissance with limited privileges.
Memory trick: Windows commands reveal network neighbors.
Credential Stuffing
Flip cardAn attack that automates login attempts using username/password pairs obtained from previous data breaches, exploiting users who reuse the same credentials across multiple services.
- Relies on real, previously breached credential pairs, not guessed passwords
- Effective due to widespread password reuse
- Mitigated by MFA, breach-password blocklists, and rate limiting
Memory trick: Stuffing = stuffing stolen keys into every door hoping one fits
PTES Post-Exploitation
Flip cardThe PTES phase after initial access focused on determining a compromised system's value, escalating privileges, harvesting data, and pivoting to additional targets.
- Follows the Exploitation phase
- Includes privilege escalation, pillaging, and lateral movement
- Feeds findings into the final Reporting phase
Memory trick: Pre-Intel-Threat-Vuln-Exploit-Post-Report: 'Please Include The Vulnerable Exploit, Post Report.'
Tailgating (Piggybacking) with Pretexting
Flip cardA physical social engineering technique where an attacker follows an authorized person through a secured entry point, often using a fabricated pretext (cover story) to justify needing help or access.
- Commonly combined with a pretext like a delivery, maintenance, or forgotten badge story
- Exploits human courtesy norms around holding doors open
- Mitigated with mantraps, badge-in-badge-out enforcement, and security awareness training
Memory trick: Tailgating: sneak in on someone else's tail, with a good story
ARP Spoofing
Flip cardAn on-path (man-in-the-middle) attack that sends forged ARP replies to associate the attacker's MAC address with a victim's or gateway's IP address, redirecting traffic through the attacker.
- Exploits the lack of authentication in ARP
- Commonly performed with tools like arpspoof or Ettercap
- Enables traffic sniffing, modification, or SSL stripping
Memory trick: ARP lies about who owns which address, funneling traffic through you.
Reflected Cross-Site Scripting (XSS)
Flip cardA web security vulnerability where malicious script injected by an attacker is immediately reflected back from the server in an HTTP response and executed by the user's browser. The script is not stored on the server.
- Script is reflected directly in the response.
- Not stored on the server (non-persistent).
- Requires user interaction (e.g., clicking a malicious link).
Memory trick: XSS: Store it, Reflect it, DOM it – three ways to inject client-side code.
Reflected XSS
Flip cardA cross-site scripting attack where malicious input is immediately echoed back by the server in the HTTP response, typically requiring a victim to click a crafted link.
- Payload travels in the request (URL/query/form) and is reflected in the response
- Not stored on the server; requires social engineering to deliver the link
- Mitigated by output encoding and Content Security Policy
Memory trick: Reflected = mirror bounces script back instantly
Nmap UDP Scan Port States
Flip cardUDP scanning in Nmap often yields 'open|filtered' because Nmap cannot distinguish a silently open UDP service from one blocked by a firewall due to the connectionless nature of UDP.
- ICMP port-unreachable = closed
- No response = open|filtered (ambiguous)
- Protocol-specific probes or -sV help resolve ambiguity
Memory trick: Silence in UDP land means 'maybe open, maybe blocked' — you must ask again
Actionable Remediation Recommendations
Flip cardReport recommendations must be specific and directly address the root cause of each finding, such as fixing weak credentials rather than generic or unrelated advice.
- Recommendations should map directly to the finding's root cause
- Overly generic recommendations (e.g., 'buy a SIEM') reduce report value
- Password-related findings typically call for policy enforcement and credential rotation
Memory trick: Fix the root, not the symptom — tailor advice to the actual finding.
Password Spraying
Flip cardAn authentication attack that tries a small set of common passwords against many user accounts to avoid triggering lockout policies.
- Low-and-slow approach across many accounts
- Avoids per-account lockout thresholds
- Often targets seasonal or default passwords
Memory trick: Spray wide, not deep — one password, many doors.
Master Service Agreement (MSA)
Flip cardA long-term contract establishing overarching legal and business terms that apply to all future work between a client and vendor.
- Governs the ongoing relationship, not one project
- Individual SOWs are created under the MSA for each engagement
- Typically covers payment terms, liability, and confidentiality baseline
Memory trick: NASOR: NDA, Authorization, SOW, MSA, RoE — each document plays a role.
Custom DNS Exfiltration Script
Flip cardDeveloping a custom script (e.g., in PowerShell, Python) to encode sensitive data into subdomain names and send them as DNS queries to a controlled external DNS server for exfiltration.
- Offers high degree of customization and stealth compared to off-the-shelf tools.
- Requires a controlled external DNS server to receive and decode queries.
- Can bypass network monitoring that focuses on common C2 traffic patterns.
Memory trick: Custom DNS queries hide data in plain sight.
Nmap ssl-cert script
Flip cardThe Nmap 'ssl-cert' script retrieves and displays detailed information about the SSL/TLS certificate presented by a service, including issuer, subject, validity dates, serial number, and public key details.
- Extracts SSL/TLS certificate details.
- Provides issuer, subject, validity, and expiration dates.
- Crucial for identifying certificate misconfigurations or weaknesses.
Memory trick: The SSL-cert reveals all about the certificate's identity.
Metasploit wordpress_login_enum
Flip cardA Metasploit auxiliary module used to enumerate valid usernames on WordPress websites. It typically achieves this by analyzing the differences in error messages or HTTP response codes returned by the login page when an invalid username is provided versus a valid one.
- Targets WordPress login pages.
- Identifies valid usernames.
- Relies on distinct error messages or response codes.
- Part of Metasploit's auxiliary scanner modules.
Memory trick: Login_enum is like a detective listening for specific whispers at the WordPress door.
Nmap OS Detection (-O)
Flip cardThe Nmap `-O` (OS detection) option attempts to determine the operating system, OS family, type, and vendor of a target host. It uses various TCP/IP stack fingerprinting techniques, including analyzing TCP ISN (Initial Sequence Number) sampling, TCP options, and IP flags.
- Identifies the operating system and its version.
- Uses TCP/IP stack fingerprinting.
- Can also guess device type (router, firewall, etc.).
- Often requires at least one open and one closed TCP port for accuracy.
Memory trick: Nmap's 'O' is for 'Operating system' identification.
Burp Suite Intruder (LFI Testing)
Flip cardBurp Suite Intruder is used to automate the testing of Local File Inclusion (LFI) vulnerabilities by systematically injecting a list of common LFI payloads into a vulnerable parameter and analyzing the server's responses.
- Automates payload injection into parameters.
- Supports various attack types (Sniper, Battering Ram, Pitchfork, Cluster Bomb).
- Essential for brute-forcing, fuzzing, and enumeration, including LFI testing.
Memory trick: Intruder systematically tries to break in with every payload.
Nmap Focused Web Enumeration
Flip cardUsing Nmap's service version detection (`-sV`) combined with web-specific scripts like `http-enum` to gather detailed information about a web server, including software versions and common directories, without being overly aggressive.
- `-sV` for service/version detection.
- `--script=http-enum` for directory and file enumeration.
- Provides focused web-specific reconnaissance.
- Less aggressive than a full `-A` scan.
Memory trick: Service Version + HTTP Enum = Web Insight
ss -tulnp
Flip cardA command-line utility in Linux used to display socket statistics, including all listening TCP and UDP ports, their numerical addresses, associated process IDs, and program names.
- Replaces or augments `netstat` in modern Linux systems.
- `-t`: TCP sockets, `-u`: UDP sockets, `-l`: listening sockets.
- `-n`: Numerical addresses, `-p`: Process ID/name.
- Excellent for service enumeration and understanding network activity.
Memory trick: SS Shows TCP/UDP Listening Processes
Windows Ping Sweep
Flip cardUsing the native 'ping' command in Windows to send ICMP echo requests to a range of IP addresses to identify active hosts on a network segment.
- Uses ICMP echo requests.
- Native Windows utility.
- Identifies active hosts (those that respond).
- Can be configured for single packets and short timeouts to reduce traffic.
Memory trick: PINGing for Friends on the Network
Nmap http-headers script
Flip cardThe Nmap 'http-headers' script retrieves and displays all HTTP response headers from a web server, which can reveal valuable information about the server software, frameworks, and technologies in use.
- Collects all HTTP response headers.
- Useful for web server fingerprinting.
- Identifies 'Server', 'X-Powered-By', and other informative banners.
Memory trick: HTTP headers reveal the web server's true identity.
Nmap Comprehensive Service & OS Scan
Flip cardUsing Nmap with `-sV` (service version detection) and `-O` (OS detection) to obtain detailed information about running services and the operating system across all ports of a target.
- `-sV` identifies service name and version.
- `-O` identifies the target's operating system.
- `-p-` scans all 65535 TCP ports.
- Provides deep reconnaissance details.
Memory trick: Service Version & OS for Deep Insight
Nmap Fast Scan with Service Version Detection
Flip cardNmap's '-F -sV' combination performs a quick scan of the 100 most common ports and attempts to determine the service and version running on any open ports. This provides an efficient initial overview of a target's exposed services.
- '-F' scans 100 most common ports (TCP).
- '-sV' performs service version detection.
- Efficient for initial reconnaissance and target profiling.
Memory trick: Fast scan with service versions gives a quick OS hint.