Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

After gaining initial access to an internal network, a penetration tester wants to identify live hosts on a subnet without generating excessive traffic. Which Nmap command would be most appropriate for host discovery using ICMP echo requests and TCP SYN to port 80?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

nmap -sn 192.168.1.0/24

Nmap's -sn flag performs a ping sweep, which by default uses ICMP echo, TCP SYN to port 80, and other probes. The other options are for port scanning or OS detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    nmap -A 192.168.1.0/24

    Why it's wrong here

    -A is an aggressive scan mode that layers OS fingerprinting (-O), version detection (-sV), default NSE scripts (-sC), and traceroute into a single run. Because these techniques all require port scan results to be useful, -A implicitly performs a full port scan across the target range, generating heavy traffic and taking considerably longer than a host discovery sweep. On a /24 subnet, this noise can trip IDS/IPS alerts and will not provide any additional benefit for the immediate goal of simply identifying which IPs are alive, making it an inefficient and risky choice at this early stage.

  • ✗

    nmap -sS 192.168.1.0/24

    Why it's wrong here

    -sS is a SYN stealth port scan, not a host discovery mechanism; it sends TCP SYN packets to a specific list of ports (commonly the top 1000) and analyzes the responses to classify ports as open, closed, or filtered. This means it only reveals liveness for hosts that happen to respond to one of those probed ports, so hosts without any open TCP ports or behind strict firewalls that drop unsolicited SYNs can be missed entirely. It also wastes network overhead by scanning hundreds of ports on every address instead of just checking whether each host is reachable, which is not the intended purpose of a post-initial-access subnet sweep.

  • ✗

    nmap -O 192.168.1.0/24

    Why it's wrong here

    -O is the flag for remote OS detection, which attempts to fingerprint the operating system by sending specially crafted TCP/IP packets and analyzing subtle differences in their responses. For this to work, Nmap first needs a port scan to identify open ports and a closed port to collect comparative probe data; if a host is alive but has no reachable open ports, -O will often fail to produce a conclusive fingerprint or may mark the host as filtered. Therefore, -O is a post-discovery enumeration technique that depends on knowing which hosts and ports are available, rather than a tool for initially discovering which IPs are up on a subnet.

  • ✓

    nmap -sn 192.168.1.0/24

    Why this is correct

    -sn, historically called -sP or "ping sweep," disables port scanning completely and tells Nmap to perform only host discovery, reporting every IP address that is currently reachable on the target subnet. On a local Ethernet network, Nmap uses ARP requests for discovery because they are highly reliable and cannot be filtered without breaking normal IP communications; for remote targets, it combines ICMP echo requests, TCP SYN probes to ports 80 and 443, and ICMP timestamp requests to determine liveness. This yields a fast, low-noise inventory of live systems, which is exactly the right first step when mapping an internal network after gaining initial access, before deciding which IPs warrant deeper port scanning.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.