CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementMedium
A penetration tester has obtained authenticated access to an internal network segment. The tester wants to quickly identify open ports and services on a range of target hosts without triggering aggressive firewall alerts. Which 'nmap' command would be the MOST appropriate for this initial reconnaissance?
- A'nmap -sV -T4 <target_IP_range>'
- B'nmap -sS -p- <target_IP_range>'
- C'nmap -sT -p 1-1024 <target_IP_range>'
- D'nmap -sA <target_IP_range>'
Show answer & explanationAnswer & explanation
Correct answer: C. 'nmap -sT -p 1-1024 <target_IP_range>'
The '-sT' (TCP connect scan) is less stealthy than '-sS' but is often preferred in internal networks where firewalls might block SYN packets or Stateful Packet Inspection (SPI) is less common, making it less likely to trigger alerts than a full SYN scan on some networks. Limiting to common ports (1-1024) reduces scan time and noise. '-sS' is often blocked by Windows firewalls by default, leading to unreliable results or alerts.
Why the other options are wrong
- A. Service version detection ('-sV') is very noisy and significantly increases scan time, making it unsuitable for a 'quick' and 'non-aggressive' scan.
- B. A SYN scan ('-sS') on all ports ('-p-') is fast but can be noisy and easily detected by modern firewalls, potentially triggering alerts.
- D. An ACK scan ('-sA') is used for firewall rule set analysis and typically doesn't determine open ports reliably on its own; it's more specialized.
Nmap TCP Connect Scan (-sT)
An 'nmap' scan type that performs a full TCP three-way handshake with the target port, making it less stealthy than a SYN scan but more reliable in certain network environments.
- Completes the full TCP handshake (SYN, SYN-ACK, ACK).
- Often used when SYN scans are blocked by firewalls or produce unreliable results.
- Leaves more traces in target logs than a SYN scan but is less aggressive than a full, unthrottled scan.
Memory trick: Nmap's scans vary; choose your stealth and reliability.