A penetration tester is performing reconnaissance on a target network and wants to identify all live hosts without sending many packets. Which TWO techniques are MOST effective for host discovery in a local subnet? (Select TWO.)
ARP scanning with arp-scan is a Layer 2 host discovery technique that broadcasts ARP requests to an IP range and identifies live hosts by their ARP replies, which include MAC addresses. It is highly effective on the local subnet because ARP is a required protocol for IP communication and cannot be blocked by host-based firewalls, making it a reliable and stealthy way to map live systems without generating TCP or UDP traffic.
Why this answer
Option A (ARP scan using arp-scan) is correct because ARP is a Layer 2 protocol that operates within the local subnet broadcast domain, and arp-scan sends a single ARP request per target IP; any live host must reply with its MAC address, making it fast, reliable, and impossible to block without breaking normal network communication. Option D (ICMP ping sweep using nmap -sn) is correct because nmap -sn performs host discovery by sending ICMP echo requests (plus TCP SYN to 443 and TCP ACK to 80 by default when run as root) and requires only one or a few packets per host, efficiently identifying live systems across a subnet. Option B (TCP SYN scan on port 80) is not a dedicated host-discovery technique; it probes only a single port and will miss hosts that are alive but not listening on port 80, while also generating more packets per host than a ping sweep.
Option C (UDP scan on port 161) targets SNMP and is unreliable for host discovery since closed UDP ports may not respond and many hosts do not run SNMP, producing false negatives. Option E (DNS zone transfer) is an information-gathering technique for enumerating DNS records, not a method for identifying live hosts on a local subnet.
Exam trap
The trap here is that candidates often overlook ARP scans because they think only ICMP or TCP techniques are valid for host discovery, but on a local subnet ARP is the most efficient and stealthy method, while ICMP ping sweeps are also correct but can be blocked by host firewalls.