EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesEasy
A penetration tester is performing a black-box assessment and needs to map the network topology of the target organization's public-facing infrastructure. They want to determine the path packets take from their source to the target, including identifying intermediate routers and hops, without relying solely on DNS lookups. Which Nmap feature or command would be most effective for this purpose?
- ANmap -sP (Ping Scan)
- BNmap -sV (Service Version Detection)
- CNmap --traceroute
- DNmap -O (OS Detection)
Show answer & explanationAnswer & explanation
Correct answer: C. Nmap --traceroute
The Nmap --traceroute option performs a traceroute-like function, actively sending packets with incrementally increasing TTL (Time To Live) values to map the network path from the source to the target, identifying each hop along the way. This is precisely what's needed for network topology mapping.
Why the other options are wrong
- A. Ping Scan (-sP) only determines if a host is live, not the path to it.
- B. Service Version Detection (-sV) identifies software versions on open ports, not network topology.
- D. OS Detection (-O) attempts to identify the operating system of the target, not the network path.
Nmap Traceroute (--traceroute)
An Nmap option that maps the network path to a target host by sending packets with increasing Time To Live (TTL) values, identifying each intermediate router (hop).
- Maps network path to target
- Identifies intermediate routers/hops
- Uses increasing TTL values
- Useful for network topology mapping
Memory trick: Traceroute traces the route, hop by hop.