A penetration tester is performing external reconnaissance against a new client. They have identified a few public IP addresses and want to quickly determine which services are listening on common ports and get an initial idea of the operating system without performing a full, aggressive scan. Which Nmap command would achieve this MOST efficiently?
- Anmap -sV -O <target_IP>
- Bnmap -sn <target_IP>
- Cnmap -sS -p- <target_IP>
- Dnmap -F -sV <target_IP>
Show answer & explanationAnswer & explanation
Correct answer: D. nmap -F -sV <target_IP>
The '-F' (Fast scan) option scans the 100 most common ports, providing a quick overview. Combining it with '-sV' performs service version detection on those open ports, and '-O' performs OS detection (though not explicitly asked for, '-sV' often implies some level of OS fingerprinting through service banners). This combination is efficient for initial service and OS identification without being overly aggressive.
Why the other options are wrong
- A. '-sV -O' performs service version and OS detection but without '-F' it scans the default 1000 ports, which is less efficient than scanning only the 100 most common ports for this quick assessment.
- B. '-sn' (ping scan) only checks if a host is up, without scanning for open ports or services.
- C. '-p-' scans all 65535 ports, which is not 'quick' or 'efficient'.
Nmap Fast Scan with Service Version Detection
Nmap's '-F -sV' combination performs a quick scan of the 100 most common ports and attempts to determine the service and version running on any open ports. This provides an efficient initial overview of a target's exposed services.
- '-F' scans 100 most common ports (TCP).
- '-sV' performs service version detection.
- Efficient for initial reconnaissance and target profiling.
Memory trick: Fast scan with service versions gives a quick OS hint.