CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationHard

A penetration tester is performing reconnaissance against a target organization's internal network. They have obtained a list of IP addresses and want to quickly determine the operating system running on each host without performing a full, intense port scan. Which Nmap option, when combined with a host discovery scan, can provide a reasonable guess of the OS?

  1. A-sV
  2. B-O
  3. C-sS
  4. D-p-
Show answer & explanation

Correct answer: B. -O

The `-O` (OS detection) Nmap option is used to attempt to determine the operating system and device type of a target host. While it works best with a few open ports, it can still provide reasonable guesses even with a host discovery scan (`-sn`) or limited port scans, making it suitable for quick OS identification.

Why the other options are wrong

  • A. `-sV` is for service version detection, not OS detection.
  • C. `-sS` is for SYN stealth port scanning, not OS detection.
  • D. `-p-` scans all 65535 ports, which is an intense port scan, contrary to the requirement to avoid one.

Nmap OS Detection (-O)

The Nmap `-O` (OS detection) option attempts to determine the operating system, OS family, type, and vendor of a target host. It uses various TCP/IP stack fingerprinting techniques, including analyzing TCP ISN (Initial Sequence Number) sampling, TCP options, and IP flags.

  • Identifies the operating system and its version.
  • Uses TCP/IP stack fingerprinting.
  • Can also guess device type (router, firewall, etc.).
  • Often requires at least one open and one closed TCP port for accuracy.

Memory trick: Nmap's 'O' is for 'Operating system' identification.

More Reconnaissance and Enumeration questions