Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is performing reconnaissance on a target network and wants to identify all live hosts without sending many packets. Which TWO techniques are MOST effective for host discovery in a local subnet? (Select TWO.)

⚠ Common exam trap

The trap here is that candidates often overlook ARP scans because they think only ICMP or TCP techniques are valid for host discovery, but on a local subnet ARP is the most efficient and stealthy method, while ICMP ping sweeps are also correct but can be blocked by host firewalls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ARP scan using arp-scan

Option A (ARP scan using arp-scan) is correct because ARP is a Layer 2 protocol that operates within the local subnet broadcast domain, and arp-scan sends a single ARP request per target IP; any live host must reply with its MAC address, making it fast, reliable, and impossible to block without breaking normal network communication. Option D (ICMP ping sweep using nmap -sn) is correct because nmap -sn performs host discovery by sending ICMP echo requests (plus TCP SYN to 443 and TCP ACK to 80 by default when run as root) and requires only one or a few packets per host, efficiently identifying live systems across a subnet. Option B (TCP SYN scan on port 80) is not a dedicated host-discovery technique; it probes only a single port and will miss hosts that are alive but not listening on port 80, while also generating more packets per host than a ping sweep. Option C (UDP scan on port 161) targets SNMP and is unreliable for host discovery since closed UDP ports may not respond and many hosts do not run SNMP, producing false negatives. Option E (DNS zone transfer) is an information-gathering technique for enumerating DNS records, not a method for identifying live hosts on a local subnet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ARP scan using arp-scan

    Why this is correct

    ARP scanning with arp-scan is a Layer 2 host discovery technique that broadcasts ARP requests to an IP range and identifies live hosts by their ARP replies, which include MAC addresses. It is highly effective on the local subnet because ARP is a required protocol for IP communication and cannot be blocked by host-based firewalls, making it a reliable and stealthy way to map live systems without generating TCP or UDP traffic.

  • ✗

    TCP SYN scan on port 80

    Why it's wrong here

    A TCP SYN scan on port 80 is a port scanning technique that probes for an open web service by sending a SYN packet and analyzing the SYN-ACK response. It is not a host discovery technique because it only tests one port, missing any live host that does not have Port 80 open, and it sends far more packets than a simple liveness probe, which increases network noise and the chance of detection by intrusion detection systems.

  • ✗

    UDP scan on port 161

    Why it's wrong here

    A UDP scan on port 161 targets the SNMP service, which is a dedicated protocol for network management, not a general host liveness indicator. UDP scans are unreliable for host discovery because closed ports often send no response or ICMP port-unreachable packets, and many systems rate-limit or drop UDP traffic entirely, so a lack of response does not definitively indicate whether a host is alive.

  • ✓

    ICMP ping sweep using nmap -sn

    Why this is correct

    An ICMP ping sweep using nmap -sn sends ICMP Echo Requests to a range of IP addresses and treats any response (Echo Reply, or even other ICMP messages like destination unreachable) as an indication that the host is alive. It is a standard Layer 3 host discovery method that uses minimal probes, but it can be less effective than ARP when ICMP is blocked by firewalls; however, it remains a core reconnaissance technique because it is quick and works across routed networks.

  • ✗

    DNS zone transfer

    Why it's wrong here

    DNS zone transfer is a DNS enumeration technique used to copy the entire zone file from a DNS server, revealing all registered hostnames and IP addresses in a domain. It is not a host discovery method because it does not actively probe for live systems—it merely retrieves configuration data, and modern DNS servers typically restrict zone transfers, making it an opportunistic reconnaissance step rather than a reliable liveness check.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.