Courseiva
mediumMultiple Choice

PT0-002 Practice Question: During an internal penetration test, a tester…

During an internal penetration test, a tester discovers that the client's network uses ARP poisoning to intercept traffic for security monitoring. The tester wants to enumerate live hosts without being detected by network monitoring tools. Which of the following is the BEST approach?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use passive network sniffing to capture broadcast traffic

Passive network sniffing (option A) is correct because it captures existing broadcast traffic such as ARP requests, DHCP, and NetBIOS announcements without sending any packets, making it invisible to the ARP-poisoning-based monitoring and other network detection tools. Since the tester only listens promiscuously, no active probes are generated that could trigger alerts or be correlated by the monitoring system. UDP scans (B) and SYN scans with decoys (C) both send packets that the monitoring infrastructure can detect, and decoys may still be flagged as anomalous. ARP requests (D) are active probes that would be observed by the ARP-poisoning monitoring setup, defeating the goal of staying undetected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use passive network sniffing to capture broadcast traffic

    Why this is correct

    Passive sniffing captures existing broadcast and multicast traffic without injecting any packets, so it generates no ARP requests that the monitoring sensors would flag. Active scanning would trigger the ARP-poisoning-based detection, so passive capture satisfies the stealth requirement.

  • ✗

    Perform a UDP scan

    Why it's wrong here

    UDP scanning sends packets to closed ports, prompting ICMP port-unreachable replies that the ARP-poisoning monitor captures, exposing the sweep. It suits enumerating UDP services such as SNMP or DNS, not stealthy host discovery on a segment where all traffic is already being intercepted.

  • ✗

    Perform a SYN scan with decoys

    Why it's wrong here

    Decoy hosts spoof source addresses, but the ARP-poisoning sensor still sees the SYN packets reaching each live host and logs the scan. Decoys suit hiding the scanner's true origin from target-side attribution, not evading a passive monitor already positioned on the segment.

  • ✗

    Use ARP requests to discover hosts

    Why it's wrong here

    ARP requests are broadcast and answered by every live host, so the poisoning sensor observes the entire discovery sweep directly. ARP scanning suits fast layer-2 host enumeration on a switched segment, but here it maximises visibility to the very monitoring the tester must avoid.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.