CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationHard
A penetration tester is performing reconnaissance against a target organization's internal network. They have obtained a list of IP addresses and want to quickly determine the operating system running on each host without performing a full, intense port scan. Which Nmap option, when combined with a host discovery scan, can provide a reasonable guess of the OS?
- A-sV
- B-O
- C-sS
- D-p-
Show answer & explanationAnswer & explanation
Correct answer: B. -O
The `-O` (OS detection) Nmap option is used to attempt to determine the operating system and device type of a target host. While it works best with a few open ports, it can still provide reasonable guesses even with a host discovery scan (`-sn`) or limited port scans, making it suitable for quick OS identification.
Why the other options are wrong
- A. `-sV` is for service version detection, not OS detection.
- C. `-sS` is for SYN stealth port scanning, not OS detection.
- D. `-p-` scans all 65535 ports, which is an intense port scan, contrary to the requirement to avoid one.
Nmap OS Detection (-O)
The Nmap `-O` (OS detection) option attempts to determine the operating system, OS family, type, and vendor of a target host. It uses various TCP/IP stack fingerprinting techniques, including analyzing TCP ISN (Initial Sequence Number) sampling, TCP options, and IP flags.
- Identifies the operating system and its version.
- Uses TCP/IP stack fingerprinting.
- Can also guess device type (router, firewall, etc.).
- Often requires at least one open and one closed TCP port for accuracy.
Memory trick: Nmap's 'O' is for 'Operating system' identification.