CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisEasy

A penetration tester has identified several open ports on a target host using an Nmap SYN scan. To determine the specific software product and version running on each open port for later CVE correlation, which Nmap option should the tester use?

  1. A-sU
  2. B-sn
  3. C-sV
  4. D-sL
Show answer & explanation

Correct answer: C. -sV

The -sV flag instructs Nmap to probe open ports and interrogate services to determine product names and version numbers, which can then be matched against CVE databases. -sU performs a UDP scan, -sn performs host discovery only (no port scan), and -sL merely lists targets without scanning.

Why the other options are wrong

  • A. -sU scans UDP ports, not version detection.
  • B. -sn only does host discovery and skips port scanning entirely.
  • D. -sL just lists targets for a DNS reverse lookup, no scanning occurs.

Nmap Version Detection (-sV)

An Nmap option that probes open ports with protocol-specific probes to identify the running service and its version number.

  • Used after discovering open ports to enrich findings
  • Often combined with -sS or -sT scans
  • Results feed directly into vulnerability/CVE correlation

Memory trick: 'V' for Version — Nmap's Voice ID for services

More Vulnerability Discovery and Analysis questions