A security analyst is preparing to scan a production network segment containing legacy medical devices that cannot be patched or rebooted. The analyst wants to identify exposed services without causing device crashes or service interruptions. Which Nmap scan technique should the analyst use?
Trap 1: TCP ACK scan with -sA and -T1
A TCP ACK scan with -sA is used to map firewall rulesets, not to identify open services. It sends ACK packets and interprets RST responses to determine filtered versus unfiltered ports, but it cannot distinguish open from closed ports. Therefore, it would not fulfill the requirement of identifying exposed services on the medical devices.
Trap 2: TCP connect scan with -sT and -T0
A TCP connect scan with -sT completes the three-way handshake, which can cause some legacy devices to allocate resources and potentially hang. Even with -T0 (paranoid timing), the full connection attempt is more intrusive than a half-open scan. This technique is not ideal when the goal is to minimize impact on fragile production devices.
Trap 3: TCP SYN scan with -sS and default timing
A TCP SYN scan with -sS and default timing sends SYN packets and may elicit RST responses, but the default timing template can still generate bursts that overwhelm fragile devices. Additionally, the half-open scan still requires raw socket privileges and may not fully avoid disruption. It is not the safest choice for legacy medical devices that are sensitive to even moderate traffic spikes.
- A
TCP SYN scan with -sS and -T2
A TCP SYN scan with -sS and -T2 (polite timing) sends SYN packets and waits for SYN-ACK or RST without completing the handshake, reducing the chance of resource exhaustion on legacy devices. The polite timing slows the scan and minimizes network bursts, making it the best balance between service discovery and device safety in this scenario.
- B
TCP ACK scan with -sA and -T1
Why it fails: A TCP ACK scan with -sA is used to map firewall rulesets, not to identify open services. It sends ACK packets and interprets RST responses to determine filtered versus unfiltered ports, but it cannot distinguish open from closed ports. Therefore, it would not fulfill the requirement of identifying exposed services on the medical devices.
- C
TCP connect scan with -sT and -T0
Why it fails: A TCP connect scan with -sT completes the three-way handshake, which can cause some legacy devices to allocate resources and potentially hang. Even with -T0 (paranoid timing), the full connection attempt is more intrusive than a half-open scan. This technique is not ideal when the goal is to minimize impact on fragile production devices.
- D
TCP SYN scan with -sS and default timing
Why it fails: A TCP SYN scan with -sS and default timing sends SYN packets and may elicit RST responses, but the default timing template can still generate bursts that overwhelm fragile devices. Additionally, the half-open scan still requires raw socket privileges and may not fully avoid disruption. It is not the safest choice for legacy medical devices that are sensitive to even moderate traffic spikes.