An incident responder needs to identify active hosts on a segmented network while minimizing the risk of triggering IDS alerts. Which Nmap technique is most appropriate for a stealthy discovery scan?
Trap 1: TCP Connect scan (-sT)
This technique utilizes the system's underlying connect() system call to establish a complete three-way handshake. Because the connection is fully realized before being dropped, it is easily detected by target operating systems and logging mechanisms, making it highly conspicuous and unsuitable for stealthy reconnaissance operations on sensitive networks.
Trap 2: UDP scan (-sU)
UDP scanning is inherently slower and less reliable than TCP techniques due to the connectionless nature of the protocol. It relies on waiting for ICMP unreachable messages, which are frequently rate-limited or blocked by modern firewalls, making it inefficient for initial host discovery compared to SYN-based TCP scanning methods.
Trap 3: Ping sweep (-sP)
While fast, traditional ICMP echo requests are frequently blocked by perimeter firewalls and host-based intrusion prevention systems. Relying solely on ICMP for discovery in modern enterprise environments often leads to incomplete results because many administrators disable ICMP responses to prevent network mapping, rendering this method unreliable for comprehensive host discovery.
- A
TCP Connect scan (-sT)
Why it fails: This technique utilizes the system's underlying connect() system call to establish a complete three-way handshake. Because the connection is fully realized before being dropped, it is easily detected by target operating systems and logging mechanisms, making it highly conspicuous and unsuitable for stealthy reconnaissance operations on sensitive networks.
- B
TCP SYN scan (-sS)
This approach performs a half-open scan by sending only SYN packets and observing the response. Since the full TCP handshake is never completed, the target service often does not log the connection as an established session, allowing the scanner to map host availability while bypassing many basic logging-based detection systems.
- C
UDP scan (-sU)
Why it fails: UDP scanning is inherently slower and less reliable than TCP techniques due to the connectionless nature of the protocol. It relies on waiting for ICMP unreachable messages, which are frequently rate-limited or blocked by modern firewalls, making it inefficient for initial host discovery compared to SYN-based TCP scanning methods.
- D
Ping sweep (-sP)
Why it fails: While fast, traditional ICMP echo requests are frequently blocked by perimeter firewalls and host-based intrusion prevention systems. Relying solely on ICMP for discovery in modern enterprise environments often leads to incomplete results because many administrators disable ICMP responses to prevent network mapping, rendering this method unreliable for comprehensive host discovery.