CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationHard

A penetration tester has identified a target web application that appears to be running on an unusual port, 8443, and uses HTTPS. They want to perform a comprehensive vulnerability scan using Nmap, including service version detection, OS detection, and common script scanning, specifically targeting this port. Which Nmap command would be MOST appropriate?

  1. Anmap -sV -O -A -p 8443 <target_IP>
  2. Bnmap -Pn -sV -sC -p 8443 <target_IP>
  3. Cnmap -sC -sV -O -p 8443 <target_IP>
  4. Dnmap -A -p 8443 <target_IP>
Show answer & explanation

Correct answer: D. nmap -A -p 8443 <target_IP>

The '-A' flag in Nmap enables 'Aggressive' scan mode, which is a shorthand for '-sV -sC -O --traceroute'. This includes service version detection (-sV), default script scanning (-sC), and OS detection (-O), exactly what's needed for a comprehensive scan. Specifying '-p 8443' targets only the identified port.

Why the other options are wrong

  • A. This option explicitly lists '-sV' and '-O', but omits '-sC' for common script scanning, making it less comprehensive than '-A'.
  • B. '-Pn' skips host discovery, which might be useful if the host is assumed to be up, but the question asks for a comprehensive scan including service/OS/scripts, and '-A' already covers these efficiently.
  • C. This option includes '-sC', '-sV', and '-O', which is correct, but '-A' is the more concise and commonly used shorthand for this combination.

Nmap Aggressive Scan (-A)

The Nmap '-A' option enables an aggressive scan, which is a combination of several advanced scan features: OS detection (-O), version detection (-sV), script scanning using the default script set (-sC), and traceroute (--traceroute). It's used for comprehensive information gathering.

  • Shorthand for -sV -sC -O --traceroute.
  • Provides comprehensive information about services, OS, and common vulnerabilities.
  • More noisy and time-consuming than basic scans.

Memory trick: Aggressive mode gathers ALL the details.

More Reconnaissance and Enumeration questions