CompTIA Network+ (N10-009)Network TroubleshootingMedium

A technician wants to determine the likely operating system running on several unidentified hosts on the network without needing valid login credentials. Which nmap option is designed for this purpose?

  1. Anmap -O
  2. Bnmap -sn
  3. Cnmap -p 1-1024
  4. Dnmap -sV
Show answer & explanation

Correct answer: A. nmap -O

The -O flag enables nmap's OS detection feature, which analyzes TCP/IP stack behavior (such as TTL values and TCP options) to guess the target's operating system. -sV detects service/version info on open ports, -sn performs a host discovery (ping) scan without port scanning, and -p specifies a port range.

Why the other options are wrong

  • B. -sn is a ping sweep that only discovers live hosts, no OS info.
  • C. -p only restricts the port range scanned, unrelated to OS detection.
  • D. -sV detects service versions on open ports, not the OS itself.

nmap OS Detection (-O)

An nmap scan option that fingerprints a target's operating system by analyzing characteristic TCP/IP stack responses.

  • -O relies on TTL, window size, and TCP option ordering.
  • Requires at least one open and one closed port for best accuracy.
  • Different from -sV, which detects application/service versions.

Memory trick: 'O is for Operating system.'

More Network Troubleshooting questions