CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisEasy
A penetration tester wants to quickly determine which ports are open on a target network while completing as few full TCP handshakes as possible to reduce log noise. Which Nmap scan type should the tester use?
- A-sU (UDP scan)
- B-sT (TCP connect scan)
- C-sS (SYN scan)
- D-sA (ACK scan)
Show answer & explanationAnswer & explanation
Correct answer: C. -sS (SYN scan)
A SYN scan (-sS) sends a SYN packet and, upon receiving a SYN/ACK, immediately sends a RST instead of completing the handshake with an ACK, making it faster and stealthier than a full connect scan.
Why the other options are wrong
- A. -sU scans UDP ports, not the stealthy TCP technique described.
- B. -sT completes the full three-way handshake, generating more logs.
- D. -sA is used for firewall rule mapping, not general port discovery.
Nmap SYN Scan (-sS)
A half-open TCP scan that sends SYN packets and resets the connection before completion, providing fast, low-footprint port discovery.
- Also called a 'half-open' scan
- Requires raw socket privileges (root/admin)
- Default scan type when running Nmap with elevated privileges
Memory trick: 'Stop, You've Understood Access' = SYN, TCP-connect, UDP, ACK