An incident handler is mapping a flat internal subnet and wants Nmap to identify live hosts without performing port scans on every address. The handler also needs the scan to work when ICMP echo requests are blocked by host-based firewalls. Which Nmap option should be used?
The -sn option performs host discovery only, skipping port scanning entirely. Nmap still sends ICMP echo, TCP SYN to port 443, TCP ACK to port 80, and an ICMP timestamp request by default, so it can detect hosts that block ICMP but respond on common TCP ports, which fits the flat subnet requirement.
Why this answer
The -sn option performs host discovery only and skips port scanning, and Nmap's default discovery probes include TCP SYN to port 443 and TCP ACK to port 80 in addition to ICMP, so hosts that block ping but expose web services are still detected. This satisfies both the discovery-only and ICMP-blocked requirements.
Exam trap
The trap here is assuming that host discovery depends on ICMP echo, when Nmap's -sn default probes also include TCP SYN and ACK to common web ports.