Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is performing internal network scanning and wants to identify live hosts on a local subnet without sending IP packets. Which method is most effective in a switched Ethernet environment?

⚠ Common exam trap

Test-takers frequently assume Nmap's `-sn` ping sweep is the standard for host discovery, overlooking that it relies on IP-layer packets, whereas ARP operates at Layer 2 and is the only method that avoids IP packets entirely on a local subnet.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

arp-scan

In a switched Ethernet environment, ARP (Address Resolution Protocol) operates at Layer 2 and does not require IP packets to discover hosts. The `arp-scan` tool sends ARP requests to the local broadcast MAC address, and live hosts respond with their MAC addresses, making it the most effective method for identifying live hosts without sending IP packets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    TCP SYN scan to common ports

    Why it's wrong here

    A TCP SYN scan transmits IP packets to common ports, directly contradicting the requirement to avoid sending IP packets, and closed ports make hosts appear dead. It is tempting because SYN scanning reliably detects live hosts, but it is the correct approach when packet transmission is permitted.

  • ✗

    Nmap ping sweep with -sn

    Why it's wrong here

    Nmap's -sn ping sweep sends ICMP echo requests, TCP SYN to ports 443 and 80, and ARP for local targets, so it transmits IP packets and fails the stated constraint. It is tempting because -sn is the standard host-discovery technique, but it suits scenarios where IP traffic is allowed.

  • ✓

    arp-scan

    Why this is correct

    arp-scan sends ARP requests, which operate at layer 2, so it discovers live hosts on the local subnet without transmitting IP packets. In a switched Ethernet environment this bypasses router boundaries and reliably maps active devices by MAC address.

  • ✗

    SNMP walk

    Why it's wrong here

    SNMP walk queries UDP port 161 on devices running an SNMP agent, so it identifies only hosts with SNMP enabled and reachable, not all live hosts, and it still sends IP packets. It is tempting because SNMP can enumerate hosts and interfaces, but it suits auditing managed network devices, not silent host discovery.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.