CAS-004 Security Operations Practice Question
A security analyst is reviewing the following command executed on a Linux server: 'nmap -sS -Pn -p 80,443 192.168.1.0/24'. Which of the following BEST describes the purpose of this command?
⚠ Common exam trap
Candidates often confuse -Pn (skip host discovery) with -sn (ping sweep), and -sS (SYN scan) with -sT (connect scan).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform a TCP SYN scan on ports 80 and 443 across the subnet, skipping host discovery
The command uses -sS for a TCP SYN scan, -Pn to skip host discovery, and -p 80,443 to target specific ports. This is a common reconnaissance technique to quickly identify web servers on a subnet without the noise of a full port scan or host discovery. The other options misinterpret the flags or the scan type.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform a ping sweep to identify live hosts on the subnet, then scan ports 80 and 443
Why it's wrong here
A ping sweep is typically done with the -sn flag (formerly -sP). The command uses -Pn, which skips host discovery entirely, not performs a ping sweep. The -sS flag indicates a SYN scan, not a ping sweep. Therefore, this option misidentifies the purpose of the command. The command is designed to scan specific ports without first checking if hosts are online.
- ✗
Perform a TCP connect scan on all ports across the subnet, including host discovery
Why it's wrong here
A TCP connect scan uses the -sT flag, not -sS. The -sS flag is for SYN scan. Also, the command specifies only ports 80 and 443, not all ports. The -Pn flag disables host discovery, not includes it. Therefore, this option misinterprets the flags and the port specification. The command is a SYN scan on specific ports with no host discovery.
- ✓
Perform a TCP SYN scan on ports 80 and 443 across the subnet, skipping host discovery
Why this is correct
The -sS flag initiates a TCP SYN scan (half-open scan), which is stealthy because it does not complete the TCP handshake. The -Pn flag disables host discovery (ping), treating all hosts as online. The -p 80,443 specifies ports 80 and 443. The target is the subnet 192.168.1.0/24. This command is used to quickly identify web servers on the network without performing a full port scan or host discovery, which can be noisy and slow.
- ✗
Perform a UDP scan on ports 80 and 443 across the subnet, skipping host discovery
Why it's wrong here
A UDP scan uses the -sU flag, not -sS. The -sS flag is for TCP SYN scan. The command does not include -sU, so it is not a UDP scan. Additionally, UDP scans on ports 80 and 443 are less common because these are typically TCP ports. The command is clearly a TCP SYN scan based on the -sS flag.
Visual reference
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.