CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester is performing network reconnaissance against a client's external IP range. They want to identify active hosts and open ports without significantly increasing the risk of detection. Which Nmap scan type is best suited for this objective while minimizing noise?

  1. Anmap -sS <target>
  2. Bnmap -O <target>
  3. Cnmap -sU <target>
  4. Dnmap -sT <target>
Show answer & explanation

Correct answer: A. nmap -sS <target>

The -sS (SYN scan or 'half-open' scan) is stealthier than a full TCP connect scan (-sT) because it does not complete the three-way handshake, making it less likely to be logged by the target system's applications.

Why the other options are wrong

  • B. The -O (OS detection) flag attempts to determine the operating system, which involves sending more probes and is typically done after initial port scanning, increasing detection risk.
  • C. The -sU (UDP scan) is used for scanning UDP ports and can be very slow and unreliable, not ideal for a general stealthy host/port discovery.
  • D. The -sT (TCP connect scan) completes the full TCP three-way handshake, making it louder and more easily detected by target systems.

Nmap SYN Scan (-sS)

A 'half-open' TCP port scan that sends a SYN packet and waits for a SYN/ACK (open) or RST (closed) response, without completing the full TCP handshake.

  • Stealthier than a full TCP connect scan.
  • Does not complete the 3-way handshake.
  • Requires root privileges to perform.

Memory trick: Nmap scans: Stealth, Connect, UDP, OS.

More Reconnaissance and Enumeration questions