CompTIA PenTest+ (PT0-003)Attacks and ExploitsEasy

A penetration tester wants to determine the specific software product and version running on each open port of a target host without performing full OS fingerprinting. Which nmap option should the tester use?

  1. A-O
  2. B-A
  3. C-sS
  4. D-sV
Show answer & explanation

Correct answer: D. -sV

The -sV flag performs service/version detection by probing open ports and comparing responses to a signature database. -sS is a stealth SYN scan, -O performs OS fingerprinting, and -A combines multiple aggressive options including OS and script scanning.

Why the other options are wrong

  • A. -O is dedicated to OS fingerprinting, not service versions.
  • B. -A is an aggressive combo scan that includes more than just version detection.
  • C. -sS only performs a TCP SYN scan to find open ports, not version info.

nmap Service Version Scan

The -sV flag in nmap probes open ports to determine the application name and version running on them.

  • -sV queries banners and behavior to fingerprint services
  • Can be combined with -p for specific ports
  • Increases scan time due to probing

Memory trick: 'Sassy Vixens Own Aggression' = -sS,-sV,-O,-A

More Attacks and Exploits questions