Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

During a penetration test, the tester wants to identify live hosts on a network without performing a full port scan. Which Nmap command is most appropriate for this task?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

nmap -sn 192.168.1.0/24

The -sn flag in Nmap performs a ping sweep (host discovery) without port scanning, sending ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests by default.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    nmap -A 192.168.1.0/24

    Why it's wrong here

    The -A flag activates aggressive scanning, combining OS detection (-O), version detection (-sV), script scanning (-sC), and traceroute. This mode requires actively probing open ports to gather service and OS fingerprints, so it inherently performs a full port scan across the subnet rather than a lightweight host-discovery ping sweep. Using -A is noisy, slow, and unnecessary when the sole objective is determining which hosts are alive.

  • ✗

    nmap -O 192.168.1.0/24

    Why it's wrong here

    The -O option instructs Nmap to perform TCP/IP stack fingerprinting to infer the operating system of each target. OS detection works by sending a series of crafted probes to both open and closed ports, so Nmap first has to discover open ports; if the host has no reachable ports, detection may fail or produce an unreliable guess. This makes -O a port-scanning technique layered on top of host discovery, not a method to simply list live hosts on the 192.168.1.0/24 network.

  • ✗

    nmap -sS 192.168.1.0/24

    Why it's wrong here

    The -sS flag runs a SYN (half-open) port scan, which sends TCP SYN packets to a list of ports on every IP in the range and watches for SYN/ACK responses. This approach focuses on enumerating open TCP services across the subnet and generates a substantial amount of traffic, even towards inactive addresses, because it indiscriminately probes numerous ports per host. For pure host discovery you want a ping sweep, not a full port scan that can trigger intrusion detection systems.

  • ✓

    nmap -sn 192.168.1.0/24

    Why this is correct

    The -sn switch, previously called -sP, disables port scanning and instructs Nmap to perform only host discovery, commonly known as a ping sweep. Nmap sends a mix of ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests, and any positive response marks the host as alive. This is the fastest and quietest way to enumerate responsive systems on 192.168.1.0/24 without revealing which services are open.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.