PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is performing host discovery on a subnet. Which TWO of the following Nmap options can be used to discover live hosts?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
-sn
Both -sn (ping sweep) and -sP (older alias for ping sweep) perform host discovery without port scanning. -sS and -sV are for port scanning and version detection respectively, not host discovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
-sn
Why this is correct
The -sn flag tells Nmap to skip port scanning entirely and perform only host discovery, sending ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and an ICMP timestamp request by default when run as root. It is the canonical ping sweep option for enumerating live hosts on a subnet without probing open ports, making it the correct choice for host discovery.
- ✗
-O
Why it's wrong here
The -O flag enables remote OS detection, which sends a series of TCP and UDP probes to fingerprint the target's operating system stack. OS detection requires discovering live hosts first and often depends on responses from open ports, so it cannot fulfill the host discovery objective itself. Using -O alone would miss hosts that are down or not responding on the probed ports, so it is incorrect for subnet host discovery.
- ✓
-sP
Why this is correct
The -sP flag is the legacy alias for ping sweep, now marked as old syntax in current Nmap versions; it performs the same host discovery actions as -sn by sending ping probes to identify live hosts. While it is deprecated, it still works for backward compatibility and accomplishes the discovery task, so it is a technically correct answer, though -sn is the modern preferred spelling.
- ✗
-sV
Why it's wrong here
The -sV flag enables version detection, which actively probes open ports to determine the software and version running on a service, such as Apache 2.4.46 or OpenSSH 8.9. Version detection is a post-discovery enumeration step that requires an initial port scan to identify open ports before interrogating them. It does not identify live hosts on a subnet, so it is wrong for host discovery.
- ✗
-sS
Why it's wrong here
The -sS flag performs a SYN stealth scan, which sends TCP SYN packets to specific ports and analyzes responses to classify each port as open, closed, or filtered. Although it may reveal a live host when it receives a response, it is fundamentally a port scanning technique, not a host discovery technique, because it targets individual ports rather than broadcasting host-alive probes. Its purpose is port enumeration, not subnet host discovery, so it is incorrect.
Visual reference
Go deeper
Related to this question
Learn chapter
Penetration Testing Tools
Key term
Port scanning
Port scanning is the process of probing a computer or network device to discover which network ports are open, closed, or filtered, revealing potential entry points for services and applications.
Key term
Nmap
Nmap is a network scanning tool used to discover hosts, services, and operating systems on a computer network.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.