CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester is performing external reconnaissance against a new client. They have identified a few public IP addresses and want to quickly determine which services are listening on common ports and get an initial idea of the operating system without performing a full, aggressive scan. Which Nmap command would achieve this MOST efficiently?

  1. Anmap -sV -O <target_IP>
  2. Bnmap -sn <target_IP>
  3. Cnmap -sS -p- <target_IP>
  4. Dnmap -F -sV <target_IP>
Show answer & explanation

Correct answer: D. nmap -F -sV <target_IP>

The '-F' (Fast scan) option scans the 100 most common ports, providing a quick overview. Combining it with '-sV' performs service version detection on those open ports, and '-O' performs OS detection (though not explicitly asked for, '-sV' often implies some level of OS fingerprinting through service banners). This combination is efficient for initial service and OS identification without being overly aggressive.

Why the other options are wrong

  • A. '-sV -O' performs service version and OS detection but without '-F' it scans the default 1000 ports, which is less efficient than scanning only the 100 most common ports for this quick assessment.
  • B. '-sn' (ping scan) only checks if a host is up, without scanning for open ports or services.
  • C. '-p-' scans all 65535 ports, which is not 'quick' or 'efficient'.

Nmap Fast Scan with Service Version Detection

Nmap's '-F -sV' combination performs a quick scan of the 100 most common ports and attempts to determine the service and version running on any open ports. This provides an efficient initial overview of a target's exposed services.

  • '-F' scans 100 most common ports (TCP).
  • '-sV' performs service version detection.
  • Efficient for initial reconnaissance and target profiling.

Memory trick: Fast scan with service versions gives a quick OS hint.

More Reconnaissance and Enumeration questions