Concept and mechanism
Reconnaissance gathers clues for a verifiable inventory. A name in an old certificate shows a historical association rather than current availability or ownership. A DNS transfer may reveal names without establishing reachability of corresponding services. Version identification also needs context: a reverse proxy can respond for several backends. Record observation point, date, account used, and test conditions. During authenticated enumeration, the identity may lack access to some objects. Conclusions should track that visibility. Avoiding the conversion of an absent result into a guarantee prevents inventory gaps being confused with effective controls.
Guided application
In a fictional rehearsal, UDP reports open|filtered and discovery gets no reply from another authorized target. The first result remains consistent with a silent service or filtering. The -Pn option permits proceeding without discovery by assuming the target is up for scanning; it does not establish that it is running. Plan additional checks within scope, considering traffic limits and the window. In reporting, associate each finding with the asset actually observed and keep additional names as candidates for confirmation. Name lists, port lists, and application inventories are related but different artifacts. This discipline helps APS reproduce problems without unnecessary production testing.
open|filtered means ambiguity; -Pn changes discovery processing rather than availability evidence.
Common pitfalls
Historical record as current state; banner as backend; no reply as powered off; login as complete coverage.
Related topics: Scope, authorization, and risk reporting · Systems, vulnerabilities, and evidence · Networks, perimeter, and sessions
Always state what observation supports and what still needs confirmation.
Reference: Nmap port states · CEH 312-50, Exam Blueprint v5.0 effective2024-04-10; Candidate Handbook v7.3 (2026-09-21)