Courseiva

GPEN Scanning and Host Discovery Practice Question

You are performing a penetration test and need to identify all live hosts on a subnet without performing a port scan. Which Nmap command should you use to accomplish this?

⚠ Common exam trap

The trap here is selecting a scan type that includes port scanning, such as -sS or -sU, when only host discovery is needed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

nmap -sn 192.168.1.0/24

The -sn flag is specifically designed for ping scans, also known as host discovery. It instructs Nmap to send discovery probes and report which hosts are up, without proceeding to port scanning. This meets the requirement of identifying live hosts on a subnet while avoiding unnecessary port scans.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    nmap -sS 192.168.1.0/24

    Why it's wrong here

    The -sS option performs a TCP SYN port scan, which scans ports on hosts that are up. It does not just discover hosts; it also attempts to identify open ports. This goes beyond the requirement of only identifying live hosts and may generate more traffic and take longer. It is not the optimal choice for host discovery only.

  • ✓

    nmap -sn 192.168.1.0/24

    Why this is correct

    The -sn option tells Nmap to perform host discovery only, without port scanning. It sends probes like ICMP echo, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp to determine if hosts are up. This is exactly what is needed to identify live hosts on a subnet without scanning ports.

  • ✗

    nmap -sV 192.168.1.0/24

    Why it's wrong here

    The -sV option enables service version detection, which probes open ports to determine the software and version. This requires port scanning first and is much more intrusive than simple host discovery. It is not appropriate for the task of merely identifying live hosts, as it performs additional scanning and analysis.

  • ✗

    nmap -sU 192.168.1.0/24

    Why it's wrong here

    The -sU option initiates a UDP port scan. This is used to find open UDP ports on hosts, not just to discover live hosts. It is slower and more complex than host discovery and can generate a lot of traffic. It is not suitable when the goal is only to list live hosts on a subnet.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.