mediumMultiple Choice
PT0-002 Practice Question: During an internal penetration test, a tester is…
During an internal penetration test, a tester is trying to identify live hosts on a network segment. The tester wants to avoid generating a high volume of traffic or alerts. Which scanning technique is most appropriate for this task?
⚠ Common exam trap
Watch out — candidates often choose a SYN stealth scan (option C) thinking it is the quietest option, but they overlook that ARP scans are even more stealthy and efficient for local subnet discovery because they avoid IP-layer detection entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ARP ping scan
An ARP ping scan (option D) is the most appropriate technique because it operates at Layer 2 (Data Link layer) using ARP requests to determine if an IP address is active on the local subnet. Since ARP traffic is confined to the local broadcast domain and does not generate IP-level packets, it produces minimal network traffic and is unlikely to trigger IDS/IPS alerts, making it ideal for stealthy host discovery on a local network segment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Full TCP connect scan on common ports
Why it's wrong here
A full TCP connect scan completes the entire three-way handshake, creating completed connections that are logged by the target's operating system and visible in netstat/connection tables. This generates substantial traffic and leaves clear forensic evidence, making it the noisiest and most easily detected approach. On an internal network, IDS/IPS and host-based monitoring will flag the sudden burst of full handshakes, so it is not suitable for stealthy host discovery.
- ✗
ICMP echo request sweep
Why it's wrong here
An ICMP echo ping sweep is unreliable because many systems and firewalls drop ICMP echo requests by default, so live hosts may remain silent. Even when hosts respond, the flood of ping packets is often logged by security devices and can trigger alerts. Additionally, modern networks may only allow ICMP for specific hosts, making this method incomplete and detectable for host discovery.
- ✗
SYN stealth scan on port 80 and 443
Why it's wrong here
A SYN stealth scan sends only the initial SYN packets and never completes the handshake, so it avoids the full connection logs of a connect scan. However, the SYN packets themselves are still inspected by stateful firewalls and intrusion detection systems, which can detect a sweeper that sends SYN probes across many hosts or ports. Because it is limited to ports 80 and 443, it will also miss any live host that does not have a web service running, making it both detectable and incomplete for host discovery.
- ✓
ARP ping scan
Why this is correct
An ARP ping scan sends Ethernet broadcast frames at Layer 2, which do not create IP-level log entries and are rarely monitored because ARP traffic is normal on any local network segment. Since every active IP host must respond to an ARP request to communicate, this is the most reliable and stealthy method for discovering live hosts on the same subnet. The tradeoff is that ARP only works locally and cannot cross routers, but for internal LAN reconnaissance it is the ideal low-traffic, low-noise technique.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.