Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium
A network security analyst is investigating an alert from an Intrusion Detection System (IDS) indicating a potential port scan. The alert shows multiple connection attempts to various ports on a single host from a single source IP address within a short time frame. Which Nmap command would an attacker typically use to perform such a scan without triggering common firewall rules designed to block full TCP connections?
- Anmap -sT <target_ip>
- Bnmap -sU <target_ip>
- Cnmap -sP <target_ip>
- Dnmap -sS <target_ip>
Show answer & explanationAnswer & explanation
Correct answer: D. nmap -sS <target_ip>
The Nmap '-sS' (SYN scan or half-open scan) option sends only SYN packets and does not complete the TCP three-way handshake, making it stealthier than a full TCP connect scan ('-sT') and less likely to be logged by traditional firewalls as a full connection.
Why the other options are wrong
- A. '-sT' performs a full TCP connect scan, which completes the three-way handshake and is easily logged by firewalls.
- B. '-sU' performs a UDP scan, which targets UDP ports, not TCP ports as implied by 'connection attempts'.
- C. '-sP' performs a ping scan (host discovery), which only checks if hosts are online, not their open ports.
Nmap SYN Scan (-sS)
A stealthy port scanning technique that sends SYN packets to target ports and analyzes the responses without completing the full TCP three-way handshake, making it harder to detect by traditional firewalls.
- Also known as 'half-open' scan
- Identifies open, closed, or filtered ports
- Does not establish a full connection
Memory trick: Network Mapper Scans: Stealthy, TCP, UDP, Ping.