CompTIA Network+ (N10-009)Network TroubleshootingHard

A technician needs to identify which hosts on a /24 subnet have port 3389 (RDP) open before applying a security patch. Which nmap command would BEST accomplish this?

  1. Anmap -p 3389 192.168.1.0/24
  2. Bnmap -sL 192.168.1.0/24
  3. Cnmap --traceroute 192.168.1.1
  4. Dnmap -sn 192.168.1.0/24
Show answer & explanation

Correct answer: A. nmap -p 3389 192.168.1.0/24

The -p flag in nmap specifies a target port to scan, and providing a CIDR range like /24 scans all hosts in that subnet for that specific port's status. This directly identifies which hosts have RDP (port 3389) open.

Why the other options are wrong

  • B. -sL performs a list scan (DNS resolution only) without actually probing hosts for open ports.
  • C. --traceroute maps the network path to a single host; it doesn't scan for open ports across a subnet.
  • D. -sn performs a ping scan to discover live hosts but does not check for open ports.

nmap Port Scanning

nmap is a network scanning tool used to discover hosts and services, including open ports, on a network.

  • -p specifies target port(s) to scan, e.g., -p 3389
  • -sn performs host discovery only (no port scan)
  • -sL lists targets and does basic reverse-DNS without actually scanning them
  • CIDR notation like /24 allows scanning an entire subnet range

Memory trick: -p for Port, -sn for 'no port', -sL for List only

More Network Troubleshooting questions