exam questions

Exam PT1-002 All Questions

View all questions & answers for the PT1-002 exam

Exam PT1-002 topic 1 question 48 discussion

Actual exam question from CompTIA's PT1-002
Question #: 48
Topic #: 1
[All PT1-002 Questions]

A penetration tester wants to scan a target network without being detected by the client's IDS. Which of the following scans is MOST likely to avoid detection?

  • A. nmap ג€"p0 ג€"T0 ג€"sS 192.168.1.10
  • B. nmap ג€"sA ג€"sV --host-timeout 60 192.168.1.10
  • C. nmap ג€"f --badsum 192.168.1.10
  • D. nmap ג€"A ג€"n 192.168.1.10
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
rogal
Highly Voted 3 years, 5 months ago
Selected Answer: A
isn't it A?
upvoted 8 times
...
bieecop
Most Recent 1 year, 10 months ago
Selected Answer: C
The "-f" option in Nmap specifies fragmented IP packets. Fragmenting packets can help bypass certain network-based intrusion detection systems that may inspect complete packets but have difficulty with fragmented packets. The "--badsum" option tells Nmap to use incorrect checksums in the packets it sends. By using incorrect checksums, Nmap attempts to evade detection by IDS systems that rely on checksum verification for packet integrity.
upvoted 1 times
...
Anarckii
1 year, 11 months ago
Selected Answer: A
-sS, -T0, and -P0. Fragmentation and badchecksum are the same thing so that is only one approach within that command. IDS as well can check for fragmentation if it is configured correctly
upvoted 1 times
bieecop
1 year, 10 months ago
Option d (nmap –p0 –T0 –sS 192.168.1.10) performs a SYN scan ("-sS") with no port scanning ("-p0") and the lowest timing template ("-T0"). While SYN scans are commonly used for stealthy scanning, the absence of port scanning may not provide useful information for the penetration tester's objectives.
upvoted 1 times
...
...
bieecop
2 years, 4 months ago
Selected Answer: A
that a may be correct
upvoted 2 times
...
bromings
2 years, 6 months ago
Selected Answer: C
C should be the correct answer. Just look at the nmap IDS evasion page and you will find these two options listed there https://nmap.org/book/man-bypass-firewalls-ids.html
upvoted 4 times
isaphiltrick
1 year, 8 months ago
I agree with C, especially since it is documented in https://nmap.org/book/man-bypass-firewalls-ids.html as to what options to use to bypass firewalls and IDS. Why dispute an official nmap guide?
upvoted 1 times
...
...
OSPFv22
2 years, 11 months ago
Selected Answer: C
-f and --badsum are both listed under nmap ids/firewall evasion. https://nmap.org/book/man-bypass-firewalls-ids.html
upvoted 4 times
TheITStudent
2 years, 9 months ago
@OSPFv22 this is an underated comment. based on this: "While this simple command is often all that is needed, advanced users often go much further. In Example 4.3, the scan is modified with four options. -p0- asks Nmap to scan every possible TCP port, -v asks Nmap to be verbose about it, -A enables aggressive tests such as remote OS detection, service/version detection, and the Nmap Scripting Engine (NSE). Finally, -T4 enables a more aggressive timing policy to speed up the scan. Example 4.3. More complex: nmap -p0- -v -A -T4 scanme.nmap.org" https://nmap.org/book/port-scanning-tutorial.html I'm not 100%... based on NMAP documentation, both A and C seem to be viable answers. -p0 will not flag the IDS MOST LIKELY since they are T0 scans (paranoid) and running -Ss, this is common knowledge. On the other hand, you have nmap documentation that specifically has -f and --badsum under the IDS/FIREWALL EVASION page... ahhh, what to choose. Thanks CompTIA.
upvoted 2 times
[Removed]
2 years, 8 months ago
I'm going to go with T0 for the sole purpose that it's on the exam objectives, but I think both answers are correct either way so it's a 50/50
upvoted 2 times
...
TheITStudent
2 years, 9 months ago
Going to go with A based on the -T0
upvoted 4 times
...
...
...
Hashlife
3 years ago
Selected Answer: A
sS is a stealth scan
upvoted 2 times
...
Charlieb123
3 years ago
Selected Answer: A
A - it's a stealth scan sS, which is specifically to scan without being detected
upvoted 3 times
...
some_specialist
3 years, 1 month ago
Selected Answer: A
There has to be a mistake on selection A, as it is the only switches that actually are meant for stealth. I'm sure it's the correct answer on the est.
upvoted 1 times
...
brandonl
3 years, 1 month ago
T0: paranoid, for IDS evasion specifically. A.
upvoted 2 times
...
sir_hiccup
3 years, 1 month ago
B is correct. The option -p0 is not correct (upper case is like -Pn but in lower case works like port parm)
upvoted 1 times
...
tokhs
3 years, 5 months ago
B is correct
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago