GPEN Scanning and Host Discovery Practice Question
You are performing a penetration test and need to identify all live hosts on a subnet without performing a port scan. Which Nmap command should you use to accomplish this?
⚠ Common exam trap
The trap here is selecting a scan type that includes port scanning, such as -sS or -sU, when only host discovery is needed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
nmap -sn 192.168.1.0/24
The -sn flag is specifically designed for ping scans, also known as host discovery. It instructs Nmap to send discovery probes and report which hosts are up, without proceeding to port scanning. This meets the requirement of identifying live hosts on a subnet while avoiding unnecessary port scans.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
nmap -sS 192.168.1.0/24
Why it's wrong here
The -sS option performs a TCP SYN port scan, which scans ports on hosts that are up. It does not just discover hosts; it also attempts to identify open ports. This goes beyond the requirement of only identifying live hosts and may generate more traffic and take longer. It is not the optimal choice for host discovery only.
- ✓
nmap -sn 192.168.1.0/24
Why this is correct
The -sn option tells Nmap to perform host discovery only, without port scanning. It sends probes like ICMP echo, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp to determine if hosts are up. This is exactly what is needed to identify live hosts on a subnet without scanning ports.
- ✗
nmap -sV 192.168.1.0/24
Why it's wrong here
The -sV option enables service version detection, which probes open ports to determine the software and version. This requires port scanning first and is much more intrusive than simple host discovery. It is not appropriate for the task of merely identifying live hosts, as it performs additional scanning and analysis.
- ✗
nmap -sU 192.168.1.0/24
Why it's wrong here
The -sU option initiates a UDP port scan. This is used to find open UDP ports on hosts, not just to discover live hosts. It is slower and more complex than host discovery and can generate a lot of traffic. It is not suitable when the goal is only to list live hosts on a subnet.
Visual reference
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.