Courseiva
Security Operations →mediumMultiple Choice

CAS-004 Security Operations Practice Question

A security analyst is reviewing the following command executed on a Linux server: 'nmap -sS -Pn -p 80,443 192.168.1.0/24'. Which of the following BEST describes the purpose of this command?

⚠ Common exam trap

Candidates often confuse -Pn (skip host discovery) with -sn (ping sweep), and -sS (SYN scan) with -sT (connect scan).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Perform a TCP SYN scan on ports 80 and 443 across the subnet, skipping host discovery

The command uses -sS for a TCP SYN scan, -Pn to skip host discovery, and -p 80,443 to target specific ports. This is a common reconnaissance technique to quickly identify web servers on a subnet without the noise of a full port scan or host discovery. The other options misinterpret the flags or the scan type.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Perform a ping sweep to identify live hosts on the subnet, then scan ports 80 and 443

    Why it's wrong here

    A ping sweep is typically done with the -sn flag (formerly -sP). The command uses -Pn, which skips host discovery entirely, not performs a ping sweep. The -sS flag indicates a SYN scan, not a ping sweep. Therefore, this option misidentifies the purpose of the command. The command is designed to scan specific ports without first checking if hosts are online.

  • ✗

    Perform a TCP connect scan on all ports across the subnet, including host discovery

    Why it's wrong here

    A TCP connect scan uses the -sT flag, not -sS. The -sS flag is for SYN scan. Also, the command specifies only ports 80 and 443, not all ports. The -Pn flag disables host discovery, not includes it. Therefore, this option misinterprets the flags and the port specification. The command is a SYN scan on specific ports with no host discovery.

  • ✓

    Perform a TCP SYN scan on ports 80 and 443 across the subnet, skipping host discovery

    Why this is correct

    The -sS flag initiates a TCP SYN scan (half-open scan), which is stealthy because it does not complete the TCP handshake. The -Pn flag disables host discovery (ping), treating all hosts as online. The -p 80,443 specifies ports 80 and 443. The target is the subnet 192.168.1.0/24. This command is used to quickly identify web servers on the network without performing a full port scan or host discovery, which can be noisy and slow.

  • ✗

    Perform a UDP scan on ports 80 and 443 across the subnet, skipping host discovery

    Why it's wrong here

    A UDP scan uses the -sU flag, not -sS. The -sS flag is for TCP SYN scan. The command does not include -sU, so it is not a UDP scan. Additionally, UDP scans on ports 80 and 443 are less common because these are typically TCP ports. The command is clearly a TCP SYN scan based on the -sS flag.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.