CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisEasy

A penetration tester wants to quickly determine which ports are open on a target network while completing as few full TCP handshakes as possible to reduce log noise. Which Nmap scan type should the tester use?

  1. A-sU (UDP scan)
  2. B-sT (TCP connect scan)
  3. C-sS (SYN scan)
  4. D-sA (ACK scan)
Show answer & explanation

Correct answer: C. -sS (SYN scan)

A SYN scan (-sS) sends a SYN packet and, upon receiving a SYN/ACK, immediately sends a RST instead of completing the handshake with an ACK, making it faster and stealthier than a full connect scan.

Why the other options are wrong

  • A. -sU scans UDP ports, not the stealthy TCP technique described.
  • B. -sT completes the full three-way handshake, generating more logs.
  • D. -sA is used for firewall rule mapping, not general port discovery.

Nmap SYN Scan (-sS)

A half-open TCP scan that sends SYN packets and resets the connection before completion, providing fast, low-footprint port discovery.

  • Also called a 'half-open' scan
  • Requires raw socket privileges (root/admin)
  • Default scan type when running Nmap with elevated privileges

Memory trick: 'Stop, You've Understood Access' = SYN, TCP-connect, UDP, ACK

More Vulnerability Discovery and Analysis questions