During an internal penetration test, an engineer uses a compromised unprivileged workstation to map the internal subnet. Which scanning technique must the engineer utilize due to the specific environmental constraints?
Make the call. Every option has a note waiting here.
Notes on all 4 options
- ACorrect: an unprivileged user cannot craft raw packets, so the scanner must rely on the operating system's full TCP connect handshake.
- BSYN scans and fragmentation both need raw socket access, which normally requires administrator or root privileges.
- CACK scans also require crafting raw packets, and they map firewall filtering rules rather than discovering open services.
- DRaw UDP probing typically needs elevated privileges and is slow and noisy, so it does not fit an unprivileged workstation.