CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationHard

A penetration tester is performing network reconnaissance against a client's perimeter. They have identified a web server and want to determine if it is running on a common port (e.g., 80, 443) or an unusual one. Additionally, they need to identify the specific web server software (e.g., Apache, Nginx, IIS) and its version. Which Nmap command would achieve this most efficiently?

  1. Anmap -Pn -sV -p 80,443 <target_IP>
  2. Bnmap -sC -sV <target_IP>
  3. Cnmap -sS -O <target_IP>
  4. Dnmap -sV -p- <target_IP>
Show answer & explanation

Correct answer: D. nmap -sV -p- <target_IP>

The command `nmap -sV -p- <target_IP>` performs a full port scan (`-p-`) to find services on all 65535 ports and then attempts to determine service/version information (`-sV`) for any open ports, which efficiently identifies web servers on both common and unusual ports along with their software and version.

Why the other options are wrong

  • A. `nmap -Pn` skips host discovery (not always desired), `-sV` does service version detection, but `-p 80,443` only scans common web ports, potentially missing web servers on unusual ports.
  • B. `nmap -sC` runs default scripts (which might include some service info but isn't as focused on versioning as -sV) and `-sV` does service/version detection, but without `-p-` it only scans the top 1000 ports, potentially missing web servers on unusual ports.
  • C. `nmap -sS` performs a SYN scan (port scanning), and `-O` attempts OS detection, but it doesn't explicitly focus on service version detection nor does `-O` scan all ports by default.

Nmap Full Port Scan with Service Version Detection

The Nmap command `nmap -sV -p-` combines a scan of all 65535 TCP ports with aggressive service and version detection, enabling identification of services on non-standard ports.

  • `-p-` scans all TCP ports (1-65535).
  • `-sV` identifies service name and version.
  • Comprehensive for discovering services on unusual ports.

Memory trick: To find ALL services and their Versions, scan ALL Ports.

More Reconnaissance and Enumeration questions