Which NMAP switch would the hacker use?

A hacker is attempting to see which ports have been left open on a network. Which NMAP switch
would the hacker use?

A hacker is attempting to see which ports have been left open on a network. Which NMAP switch
would the hacker use?

A.
-sO

B.
-sP

C.
-sS

D.
-sU



Leave a Reply 12

Your email address will not be published. Required fields are marked *


Mac

Mac

I agree answer C a -sS is a stealth ACK half open scan, A is -sO is OS typing. Show answer is wrong

Km

Km

Hi There, I am about to sit for CEHv8 exam. saw your comments and i agree C is the correct answer. could you please tell of all the questions are updated on AIOtestking?

nash

nash

-sO is protocol scan and not OS. OS only if -O switch is used. Protocol scan indirectly answers the ports that are open since each well known port is tied to a know service.

EC

EC

-sO is protocol, includes ports, but -sS is the real portscan option. What counts is what they approve, and so this is the best option

just fuck your self

just fuck your self

no idea.

but sO scans includes TCP / UDP / ICMP
sS only includes TCP

just fuck your self

just fuck your self

*sS only uses TCP SYN

None

None

On This web says the correct answer is C:

https://quizlet.com/79692465/ceh-class-notes-flash-cards/
(press ctrl+f and search for this question’s title)

Joshua Dreifreund

Joshua Dreifreund

That sight probably used this site as the source, or else they both used the same source.
-sO is a better answer.
-sS is only working if you also use -p-

Joshua Dreifreund

Joshua Dreifreund

also I forgot to say that -sS is a SYN scan, so only works on TCP. What if there are UDP ports open?
“The flag -sO tells Nmap to perform an IP Protocol Scan. This type of scan iterates through the protocols found in the file nmap-protocols, and creates IP packets for every entry. For the IP protocols TCP, ICMP, UDP, IGMP, and SCTP, Nmap will set valid header values but for the rest, an empty IP packet will be used.”

-sP is a ping scan, looking for hosts that are up.
-sU will scan using UDP.

So, the best answer is -sO

Curtis

Curtis

How is -sO the ‘best’ answer when it gives you ZERO port information???