CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisHard

A penetration tester wants to run an Nmap scan against a subnet and have the results automatically stored in the Metasploit Framework database for later use by exploit modules, all without leaving the msfconsole prompt. Which command should the tester use?

  1. Adb_import
  2. Bhosts
  3. Cdb_nmap
  4. Dnmap
Show answer & explanation

Correct answer: C. db_nmap

The db_nmap command runs an Nmap scan directly from within msfconsole and automatically parses and stores the results in the connected Metasploit database.

Why the other options are wrong

  • A. db_import only loads previously saved scan output files (e.g., XML), it does not run a new scan.
  • B. 'hosts' only displays already-stored host data; it does not perform scanning.
  • D. Running plain 'nmap' from msfconsole executes the scan but does not store results in the database.

db_nmap

A Metasploit Framework console command that runs Nmap and automatically imports the scan results into the active project database.

  • Requires an active database connection (db_status)
  • Results can be viewed later with 'hosts' and 'services'
  • Streamlines recon-to-exploitation workflow

Memory trick: 'Database Never Manually Imports' — db_nmap does it live

More Vulnerability Discovery and Analysis questions