EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesMedium

A penetration tester is tasked with identifying the operating systems running on a target's internal network hosts. They have already performed a basic port scan and identified several open ports. To accurately determine the OS, which Nmap scan type would be most appropriate and effective without being overly intrusive?

  1. ANmap -O (OS detection scan)
  2. BNmap -sN (Null scan)
  3. CNmap -sA (ACK scan)
  4. DNmap -sS (SYN stealth scan)
Show answer & explanation

Correct answer: A. Nmap -O (OS detection scan)

The Nmap -O option is specifically designed for operating system detection. It analyzes various TCP/IP stack characteristics to fingerprint the target OS, which directly addresses the objective.

Why the other options are wrong

  • B. Null scan (-sN) is a stealthy port scan method that exploits TCP flag behavior, not for OS detection.
  • C. ACK scan (-sA) is used to map firewall rulesets and determine if a port is filtered, not for OS detection.
  • D. SYN stealth scan (-sS) is primarily for port scanning with stealth, not for OS detection.

Nmap OS Detection

Nmap's OS detection feature uses a series of TCP and UDP probes to analyze responses and infer the operating system running on a target host.

  • Activated with the -O option.
  • Analyzes TCP/IP stack implementation details (e.g., initial sequence numbers, TCP window sizes, IP ID fields).
  • Can be less accurate if firewalls or network devices modify responses.

Memory trick: Nmap's many maps, each for a different task, know your purpose.

More Reconnaissance Techniques questions