CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationHard
A penetration tester has identified a target web application that appears to be running on an unusual port, 8443, and uses HTTPS. They want to perform a comprehensive vulnerability scan using Nmap, including service version detection, OS detection, and common script scanning, specifically targeting this port. Which Nmap command would be MOST appropriate?
- Anmap -sV -O -A -p 8443 <target_IP>
- Bnmap -Pn -sV -sC -p 8443 <target_IP>
- Cnmap -sC -sV -O -p 8443 <target_IP>
- Dnmap -A -p 8443 <target_IP>
Show answer & explanationAnswer & explanation
Correct answer: D. nmap -A -p 8443 <target_IP>
The '-A' flag in Nmap enables 'Aggressive' scan mode, which is a shorthand for '-sV -sC -O --traceroute'. This includes service version detection (-sV), default script scanning (-sC), and OS detection (-O), exactly what's needed for a comprehensive scan. Specifying '-p 8443' targets only the identified port.
Why the other options are wrong
- A. This option explicitly lists '-sV' and '-O', but omits '-sC' for common script scanning, making it less comprehensive than '-A'.
- B. '-Pn' skips host discovery, which might be useful if the host is assumed to be up, but the question asks for a comprehensive scan including service/OS/scripts, and '-A' already covers these efficiently.
- C. This option includes '-sC', '-sV', and '-O', which is correct, but '-A' is the more concise and commonly used shorthand for this combination.
Nmap Aggressive Scan (-A)
The Nmap '-A' option enables an aggressive scan, which is a combination of several advanced scan features: OS detection (-O), version detection (-sV), script scanning using the default script set (-sC), and traceroute (--traceroute). It's used for comprehensive information gathering.
- Shorthand for -sV -sC -O --traceroute.
- Provides comprehensive information about services, OS, and common vulnerabilities.
- More noisy and time-consuming than basic scans.
Memory trick: Aggressive mode gathers ALL the details.