CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester is evaluating a client's external network perimeter. They perform an Nmap scan with the command: `nmap -sV -O -p 1-65535 <target_IP>`. Which of the following statements accurately describes the information this scan aims to gather and its characteristics?

  1. AIt performs a stealthy SYN scan to identify open ports without revealing service versions.
  2. BIt is a UDP scan designed to find open UDP ports and their associated services.
  3. CIt attempts to identify service versions and operating systems across all TCP ports, making it relatively noisy.
  4. DIt uses a full TCP connect scan to detect only common ports, avoiding OS detection for stealth.
Show answer & explanation

Correct answer: C. It attempts to identify service versions and operating systems across all TCP ports, making it relatively noisy.

The `-sV` flag enables service version detection, and `-O` enables OS detection. The `-p 1-65535` specifies scanning all TCP ports. This combination makes the scan very comprehensive but also very noisy and easily detectable due to the extensive probing required for version and OS fingerprinting.

Why the other options are wrong

  • A. The `-sV` and `-O` flags are not for stealth; they actively probe the target, and the scan type is not specified as SYN by default with these flags.
  • B. This is not a UDP scan; UDP scans require the `-sU` flag. This command targets TCP ports.
  • D. This command scans all TCP ports (1-65535), not just common ones, and explicitly includes OS detection (`-O`), which increases noise, not stealth.

Nmap Service/OS Detection

Nmap's `-sV` flag probes open ports to determine the service name, version, and product, while `-O` attempts to identify the operating system, often by analyzing TCP/IP stack fingerprints.

  • Adds significant time to scan duration.
  • Increases network traffic and detection risk.
  • Provides valuable intelligence for exploit selection.

Memory trick: Nmap flags: Service, OS, Ports, Stealth.

More Reconnaissance and Enumeration questions