Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium

A network security analyst is investigating an alert from an Intrusion Detection System (IDS) indicating a potential port scan. The alert shows multiple connection attempts to various ports on a single host from a single source IP address within a short time frame. Which Nmap command would an attacker typically use to perform such a scan without triggering common firewall rules designed to block full TCP connections?

  1. Anmap -sT <target_ip>
  2. Bnmap -sU <target_ip>
  3. Cnmap -sP <target_ip>
  4. Dnmap -sS <target_ip>
Show answer & explanation

Correct answer: D. nmap -sS <target_ip>

The Nmap '-sS' (SYN scan or half-open scan) option sends only SYN packets and does not complete the TCP three-way handshake, making it stealthier than a full TCP connect scan ('-sT') and less likely to be logged by traditional firewalls as a full connection.

Why the other options are wrong

  • A. '-sT' performs a full TCP connect scan, which completes the three-way handshake and is easily logged by firewalls.
  • B. '-sU' performs a UDP scan, which targets UDP ports, not TCP ports as implied by 'connection attempts'.
  • C. '-sP' performs a ping scan (host discovery), which only checks if hosts are online, not their open ports.

Nmap SYN Scan (-sS)

A stealthy port scanning technique that sends SYN packets to target ports and analyzes the responses without completing the full TCP three-way handshake, making it harder to detect by traditional firewalls.

  • Also known as 'half-open' scan
  • Identifies open, closed, or filtered ports
  • Does not establish a full connection

Memory trick: Network Mapper Scans: Stealthy, TCP, UDP, Ping.

More Network Intrusion Analysis questions