CompTIA PenTest+ (PT0-003)Attacks and ExploitsEasy
A penetration tester wants to determine the specific software product and version running on each open port of a target host without performing full OS fingerprinting. Which nmap option should the tester use?
- A-O
- B-A
- C-sS
- D-sV
Show answer & explanationAnswer & explanation
Correct answer: D. -sV
The -sV flag performs service/version detection by probing open ports and comparing responses to a signature database. -sS is a stealth SYN scan, -O performs OS fingerprinting, and -A combines multiple aggressive options including OS and script scanning.
Why the other options are wrong
- A. -O is dedicated to OS fingerprinting, not service versions.
- B. -A is an aggressive combo scan that includes more than just version detection.
- C. -sS only performs a TCP SYN scan to find open ports, not version info.
nmap Service Version Scan
The -sV flag in nmap probes open ports to determine the application name and version running on them.
- -sV queries banners and behavior to fingerprint services
- Can be combined with -p for specific ports
- Increases scan time due to probing
Memory trick: 'Sassy Vixens Own Aggression' = -sS,-sV,-O,-A