CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementHard

A penetration tester has successfully gained a foothold on a Linux web server. During post-exploitation, the tester discovers that the server has multiple network interfaces, one connected to the internal corporate network and another to a highly restricted DMZ segment. The tester wants to scan the DMZ segment from the compromised web server. Which of the following Nmap commands, when executed on the compromised server, would be MOST effective for this task while attempting to avoid detection by common IDS/IPS rules looking for full TCP connects?

  1. A`nmap -sF 192.168.2.0/24`
  2. B`nmap -sU 192.168.2.0/24`
  3. C`nmap -sS 192.168.2.0/24`
  4. D`nmap -sT 192.168.2.0/24`
Show answer & explanation

Correct answer: C. `nmap -sS 192.168.2.0/24`

The `-sS` (SYN scan or half-open scan) option in Nmap is often preferred for stealth over a full TCP connect scan (`-sT`). It works by sending a SYN packet and, upon receiving a SYN/ACK, immediately sending an RST packet instead of completing the three-way handshake. This leaves no full connection logs on the target system, making it less likely to be detected by traditional IDS/IPS systems looking for completed connections.

Why the other options are wrong

  • A. The `-sF` (FIN scan) is a stealth scan that sends only a FIN packet. It can be effective but often blocked by modern firewalls and may not work against all OS types (e.g., Windows typically responds to FIN with RST regardless of port state).
  • B. The `-sU` (UDP scan) is used for scanning UDP ports, which is a different protocol and not the primary method for finding open TCP services, and it can be slow and unreliable without specific UDP service knowledge.
  • D. The `-sT` (TCP Connect scan) performs a full TCP three-way handshake, which is easily logged and detected by IDS/IPS systems, making it less stealthy.

Nmap SYN Scan (-sS)

A 'half-open' Nmap scan technique that sends a SYN packet and, if a SYN/ACK is received, immediately sends an RST, avoiding a full TCP handshake for stealth.

  • Does not complete the TCP three-way handshake.
  • Less likely to be logged by target systems.
  • Requires raw packet privileges.

Memory trick: SYN Scans are Silent Network Ninjas.

More Post-exploitation and Lateral Movement questions