CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationEasy
A penetration tester is performing a black-box assessment against a client's external network. They are attempting to identify hosts that might be running an FTP service. They want to scan for the default FTP port (21/TCP) and quickly gather basic information about any detected service, including its version. Which Nmap command is MOST appropriate for this specific task?
- Anmap -p 21 -O <target_IP>
- Bnmap -p 21 -sS <target_IP>
- Cnmap -p 21 --script ftp-anon <target_IP>
- Dnmap -p 21 -sV <target_IP>
Show answer & explanationAnswer & explanation
Correct answer: D. nmap -p 21 -sV <target_IP>
The 'nmap -p 21 -sV' command specifically targets port 21 and performs service version detection ('-sV'). This will identify if an FTP service is running and attempt to determine its version, which is precisely what the tester needs for basic information gathering.
Why the other options are wrong
- A. This command attempts OS detection on port 21, but not service version detection.
- B. This command only performs a SYN scan on port 21 to check if it's open, but does not attempt to determine the service version.
- C. This command runs a specific script ('ftp-anon') to check for anonymous FTP login, which is more advanced than simply gathering basic service version information.
Nmap Service Version Detection (-sV)
The Nmap '-sV' option performs service version detection on open ports. It attempts to determine the exact service and its version running on a port, which is crucial for identifying potential vulnerabilities associated with specific software versions.
- Identifies the application and its version on open ports.
- Works by sending probes and analyzing responses.
- Essential for targeted vulnerability research.
Memory trick: Service Version tells you exactly what's serving.