A security analyst is using Nmap to discover live hosts on a subnet without performing a port scan. Which Nmap option should the analyst use to achieve this?
-sn is the Nmap option for a ping scan, which disables port scanning and only performs host discovery. It sends ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and an ICMP timestamp request to determine if a host is up. This exactly matches the analyst's requirement to discover live hosts without scanning ports.
Why this answer
The -sn option in Nmap performs a ping scan, which is used for host discovery only. It disables port scanning and uses a combination of ICMP and TCP probes to determine if hosts are online. This is the correct choice for identifying live hosts without scanning ports.
The other options either perform port scans or are deprecated.
Exam trap
The trap here is confusing host discovery options with port scanning options, or using a deprecated flag like -sP instead of the current -sn.