CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationEasy

A penetration tester is conducting an external black-box assessment against a client's network. They want to identify publicly exposed services and their associated versions running on common ports without generating excessive traffic that might trigger intrusion detection systems. Which Nmap command would be most appropriate for this initial reconnaissance phase?

  1. Anmap -O -sS <target_IP>
  2. Bnmap -sT -sV <target_IP>
  3. Cnmap -p 1-65535 -sS -sV <target_IP>
  4. Dnmap -sS -sV -F <target_IP>
Show answer & explanation

Correct answer: D. nmap -sS -sV -F <target_IP>

The `-sS` flag performs a SYN scan, which is stealthier than a full TCP connect scan. The `-sV` flag attempts to determine service/version information. The `-F` flag (fast scan) scans only the 100 most common ports, reducing traffic and making it suitable for initial, less intrusive reconnaissance.

Why the other options are wrong

  • A. The `-O` flag attempts OS detection, which is not the primary goal here (service versions), and this command doesn't limit the port range, potentially leading to excessive traffic.
  • B. The `-sT` flag performs a full TCP connect scan, which is louder and more prone to detection than a SYN scan.
  • C. Scanning all 65535 ports will generate significant traffic and take a long time, potentially triggering IDS.

Nmap Fast Scan (-F)

The Nmap `-F` (fast scan) option scans only the 100 most common ports, significantly reducing scan time and network traffic compared to scanning all 65535 ports.

  • Scans 100 most common ports
  • Reduces scan time and network traffic
  • Useful for quick, less intrusive reconnaissance

Memory trick: Nmap's Fast Scan is a Quick Way to Find Public Services.

More Reconnaissance and Enumeration questions