CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisEasy

A client has requested a penetration test of their internal network. During the reconnaissance phase, the tester needs to identify all active hosts and their associated operating systems on a specific `/24` subnet without causing significant network disruption. Which Nmap command would best achieve this objective?

  1. A`nmap -sV -p- 192.168.1.0/24`
  2. B`nmap -sn -PE 192.168.1.0/24`
  3. C`nmap -sU -sS 192.168.1.0/24`
  4. D`nmap -sS -O 192.168.1.0/24`
Show answer & explanation

Correct answer: D. `nmap -sS -O 192.168.1.0/24`

The `nmap -sS -O` command performs a TCP SYN scan (stealthy and fast) and attempts OS detection, which aligns with the goal of identifying active hosts and their operating systems without significant disruption.

Why the other options are wrong

  • A. `nmap -sV -p-` performs service version detection and scans all 65535 ports, which is much more intrusive and time-consuming than required for initial host and OS identification.
  • B. `nmap -sn` performs a ping scan (host discovery only) and explicitly disables port scanning, thus it will not detect operating systems. `-PE` enables ICMP echo request, which is part of host discovery but doesn't aid OS detection alone.
  • C. `nmap -sU` performs a UDP scan, which can be very slow and is not primarily for OS detection. Combining it with `-sS` would be for port scanning, not just host and OS identification as requested without disruption.

Nmap OS Detection

Nmap's capability to identify the operating system running on a target host by analyzing various network responses.

  • Uses TCP/IP fingerprinting.
  • Requires at least one open and one closed TCP port for accuracy.
  • Can be performed with the `-O` flag.

Memory trick: Nmap reveals hidden hosts and their digital identities.

More Vulnerability Discovery and Analysis questions