CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationEasy

A penetration tester is evaluating a client's external network. They want to identify open ports and services, but need to minimize the risk of detection by intrusion detection systems (IDS). Which Nmap scan type is best suited for this objective?

  1. AUDP Scan (-sU)
  2. BFIN Scan (-sF)
  3. CSYN Stealth Scan (-sS)
  4. DTCP Connect Scan (-sT)
Show answer & explanation

Correct answer: C. SYN Stealth Scan (-sS)

The SYN Stealth Scan (-sS) is designed to be less detectable by firewalls and IDS because it does not complete the full TCP three-way handshake, making it a 'half-open' scan.

Why the other options are wrong

  • A. The UDP Scan is for UDP ports, not typically used for stealth against IDS for TCP services.
  • B. The FIN Scan can be stealthy but is less reliable against Windows machines and is not as universally effective as SYN stealth for general port scanning.
  • D. The TCP Connect Scan completes the full TCP handshake, making it easily detectable by IDS.

Nmap SYN Stealth Scan

A type of Nmap port scan that sends a SYN packet and waits for a SYN/ACK or RST, without completing the full TCP three-way handshake. This 'half-open' technique makes it less detectable by firewalls and intrusion detection systems (IDS) compared to a full TCP Connect Scan.

  • Does not complete the TCP three-way handshake.
  • Sends only a SYN packet and analyzes the response.
  • Less likely to be logged by target systems.
  • Requires raw packet privileges.

Memory trick: Stealthy SYN avoids the full handshake, like a ninja slipping through the door.

More Reconnaissance and Enumeration questions