PT0-002 Reconnaissance and Enumeration Practice Question
You are performing a network scan and need to identify live hosts on a subnet without triggering firewalls that block ICMP. Which technique should you use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ARP scan with arp-scan
Using ARP scan (arp-scan) works on local networks and does not rely on ICMP, making it effective even when ICMP is blocked. It sends ARP requests and listens for replies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ARP scan with arp-scan
Why this is correct
ARP scan with arp-scan is the correct choice because ARP requests operate at Layer 2, directly querying each host on the local broadcast domain. Since ARP traffic is encapsulated in Ethernet frames, IP-based firewalls and host-based packet filters cannot intercept or block these probes, making ARP the most reliable method for discovering live hosts on the same subnet. Additionally, arp-scan sends gratuitous ARP requests and parses replies, efficiently mapping all active MAC and IP addresses without relying on higher-layer protocols.
- ✗
Ping sweep with nmap -sn
Why it's wrong here
A ping sweep with nmap -sn is incorrect because by default Nmap sends IP-based probes such as ICMP echo requests, TCP SYN to port 443, and TCP ACK to port 80. Many hosts and firewalls are configured to drop ICMP echo requests entirely, and aggressive network policies can also filter the TCP probes, causing live hosts to be missed. While Nmap may fall back to ARP when run with root privileges on a local subnet, the standard -sn behavior explicitly depends on Layer 3 and Layer 4 packets, which are substantially less reliable than a pure Layer 2 ARP scan.
- ✗
TCP SYN ping with nmap -PS
Why it's wrong here
A TCP SYN ping with nmap -PS sends SYN packets to a specified port (commonly port 80) and considers a host alive if it receives a SYN/ACK or RST response. This is a Layer 3/4 probe, so it is subject to stateful firewall inspection, egress filtering, and rate limiting; if the destination port is closed or filtered, the absence of a response does not necessarily mean the host is down. Furthermore, SYN pings can trigger intrusion detection or prevention systems because they resemble the initial stage of a port scan, reducing their stealth and reliability as a pure host-discovery technique.
- ✗
UDP scan with nmap -sU
Why it's wrong here
A UDP scan with nmap -sU is designed for port discovery, not host discovery, and is inherently unreliable for finding live hosts. UDP is connectionless, so most services do not reply to unsolicited packets, and the scanner often relies on ICMP port-unreachable responses to infer host status—responses that are frequently rate-limited or filtered by firewalls. Additionally, UDP scanning can be extremely slow because of retransmission timeouts, making it a poor choice for quickly identifying active systems compared to ARP, which provides immediate, unambiguous replies.
Visual reference
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.