CEH Scanning Networks and Enumeration Practice Question
A security analyst is using Nmap to discover live hosts on a subnet without performing a port scan. Which Nmap option should the analyst use to achieve this?
⚠ Common exam trap
Watch out — candidates often confuse host discovery options with port scanning options, or using a deprecated flag like -sP instead of the current -sn.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
-sn
The -sn option in Nmap performs a ping scan, which is used for host discovery only. It disables port scanning and uses a combination of ICMP and TCP probes to determine if hosts are online. This is the correct choice for identifying live hosts without scanning ports. The other options either perform port scans or are deprecated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
-sP
Why it's wrong here
-sP was the older option for a ping scan in previous versions of Nmap. In modern Nmap, -sP has been replaced by -sn. Using -sP may still work in some versions for backward compatibility, but it is deprecated and not the current recommended option. The analyst should use the current standard to ensure compatibility and correct behavior.
- ✗
-sU
Why it's wrong here
-sU specifies a UDP scan, which scans UDP ports on target hosts. This is not a host discovery technique; it is a port scanning technique. Using -sU would perform UDP port scans, which is the opposite of what the analyst wants. It would not achieve the goal of simply identifying live hosts without port scanning.
- ✓
-sn
Why this is correct
-sn is the Nmap option for a ping scan, which disables port scanning and only performs host discovery. It sends ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and an ICMP timestamp request to determine if a host is up. This exactly matches the analyst's requirement to discover live hosts without scanning ports.
- ✗
-F
Why it's wrong here
-F enables fast mode, which scans only the top 100 ports instead of the default 1000. This is a port scanning optimization, not a host discovery method. It still performs port scans, which the analyst wants to avoid. Therefore, -F does not meet the requirement of discovering live hosts without port scanning.
Visual reference
Go deeper
Related to this question
Learn chapter
Scanning Networks
Key term
Active reconnaissance
Active reconnaissance is the process of directly interacting with a target system or network to gather information, often through scanning and probing.
Key term
Nmap Scanning
Nmap scanning is a method used to discover devices running on a network and find open ports, services, and security weaknesses.
About these practice questions
This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.