CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisHard
A penetration tester wants to run an Nmap scan against a subnet and have the results automatically stored in the Metasploit Framework database for later use by exploit modules, all without leaving the msfconsole prompt. Which command should the tester use?
- Adb_import
- Bhosts
- Cdb_nmap
- Dnmap
Show answer & explanationAnswer & explanation
Correct answer: C. db_nmap
The db_nmap command runs an Nmap scan directly from within msfconsole and automatically parses and stores the results in the connected Metasploit database.
Why the other options are wrong
- A. db_import only loads previously saved scan output files (e.g., XML), it does not run a new scan.
- B. 'hosts' only displays already-stored host data; it does not perform scanning.
- D. Running plain 'nmap' from msfconsole executes the scan but does not store results in the database.
db_nmap
A Metasploit Framework console command that runs Nmap and automatically imports the scan results into the active project database.
- Requires an active database connection (db_status)
- Results can be viewed later with 'hosts' and 'services'
- Streamlines recon-to-exploitation workflow
Memory trick: 'Database Never Manually Imports' — db_nmap does it live