CompTIA Network+ (N10-009)Network TroubleshootingMedium
A technician wants to determine the likely operating system running on several unidentified hosts on the network without needing valid login credentials. Which nmap option is designed for this purpose?
- Anmap -O
- Bnmap -sn
- Cnmap -p 1-1024
- Dnmap -sV
Show answer & explanationAnswer & explanation
Correct answer: A. nmap -O
The -O flag enables nmap's OS detection feature, which analyzes TCP/IP stack behavior (such as TTL values and TCP options) to guess the target's operating system. -sV detects service/version info on open ports, -sn performs a host discovery (ping) scan without port scanning, and -p specifies a port range.
Why the other options are wrong
- B. -sn is a ping sweep that only discovers live hosts, no OS info.
- C. -p only restricts the port range scanned, unrelated to OS detection.
- D. -sV detects service versions on open ports, not the OS itself.
nmap OS Detection (-O)
An nmap scan option that fingerprints a target's operating system by analyzing characteristic TCP/IP stack responses.
- -O relies on TTL, window size, and TCP option ordering.
- Requires at least one open and one closed port for best accuracy.
- Different from -sV, which detects application/service versions.
Memory trick: 'O is for Operating system.'