CompTIA Network+ (N10-009)Network TroubleshootingHard
A technician needs to identify which hosts on a /24 subnet have port 3389 (RDP) open before applying a security patch. Which nmap command would BEST accomplish this?
- Anmap -p 3389 192.168.1.0/24
- Bnmap -sL 192.168.1.0/24
- Cnmap --traceroute 192.168.1.1
- Dnmap -sn 192.168.1.0/24
Show answer & explanationAnswer & explanation
Correct answer: A. nmap -p 3389 192.168.1.0/24
The -p flag in nmap specifies a target port to scan, and providing a CIDR range like /24 scans all hosts in that subnet for that specific port's status. This directly identifies which hosts have RDP (port 3389) open.
Why the other options are wrong
- B. -sL performs a list scan (DNS resolution only) without actually probing hosts for open ports.
- C. --traceroute maps the network path to a single host; it doesn't scan for open ports across a subnet.
- D. -sn performs a ping scan to discover live hosts but does not check for open ports.
nmap Port Scanning
nmap is a network scanning tool used to discover hosts and services, including open ports, on a network.
- -p specifies target port(s) to scan, e.g., -p 3389
- -sn performs host discovery only (no port scan)
- -sL lists targets and does basic reverse-DNS without actually scanning them
- CIDR notation like /24 allows scanning an entire subnet range
Memory trick: -p for Port, -sn for 'no port', -sL for List only