Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is using Nmap to perform host discovery on a target network 192.168.1.0/24. The tester wants to identify live hosts without scanning ports. Which Nmap command should be used?

⚠ Common exam trap

Watch out — candidates often confuse `-sn` with `-sS` or `-A`, mistakenly thinking that a stealth scan or aggressive scan is needed for host discovery, when in fact `-sn` is the dedicated, port-free host discovery option.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

nmap -sn 192.168.1.0/24

The `-sn` flag in Nmap performs a ping sweep (host discovery) without scanning any ports. It sends ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests by default to determine which hosts are alive on the 192.168.1.0/24 network, making it the ideal choice for identifying live hosts without port scanning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    nmap -A 192.168.1.0/24

    Why it's wrong here

    Aggressive scan includes port scanning, OS detection, etc.

  • ✗

    nmap -sS 192.168.1.0/24

    Why it's wrong here

    SYN scan performs port scanning, not just host discovery.

  • ✗

    nmap -sV 192.168.1.0/24

    Why it's wrong here

    Version detection requires open ports and scans services.

  • ✓

    nmap -sn 192.168.1.0/24

    Why this is correct

    Ping sweep discovers live hosts without port scanning.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.