PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is performing internal network scanning and wants to identify live hosts on a local subnet without sending IP packets. Which method is most effective in a switched Ethernet environment?
⚠ Common exam trap
Test-takers frequently assume Nmap's `-sn` ping sweep is the standard for host discovery, overlooking that it relies on IP-layer packets, whereas ARP operates at Layer 2 and is the only method that avoids IP packets entirely on a local subnet.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
arp-scan
In a switched Ethernet environment, ARP (Address Resolution Protocol) operates at Layer 2 and does not require IP packets to discover hosts. The `arp-scan` tool sends ARP requests to the local broadcast MAC address, and live hosts respond with their MAC addresses, making it the most effective method for identifying live hosts without sending IP packets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
TCP SYN scan to common ports
Why it's wrong here
A TCP SYN scan transmits IP packets to common ports, directly contradicting the requirement to avoid sending IP packets, and closed ports make hosts appear dead. It is tempting because SYN scanning reliably detects live hosts, but it is the correct approach when packet transmission is permitted.
- ✗
Nmap ping sweep with -sn
Why it's wrong here
Nmap's -sn ping sweep sends ICMP echo requests, TCP SYN to ports 443 and 80, and ARP for local targets, so it transmits IP packets and fails the stated constraint. It is tempting because -sn is the standard host-discovery technique, but it suits scenarios where IP traffic is allowed.
- ✓
arp-scan
Why this is correct
arp-scan sends ARP requests, which operate at layer 2, so it discovers live hosts on the local subnet without transmitting IP packets. In a switched Ethernet environment this bypasses router boundaries and reliably maps active devices by MAC address.
- ✗
SNMP walk
Why it's wrong here
SNMP walk queries UDP port 161 on devices running an SNMP agent, so it identifies only hosts with SNMP enabled and reachable, not all live hosts, and it still sends IP packets. It is tempting because SNMP can enumerate hosts and interfaces, but it suits auditing managed network devices, not silent host discovery.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.