PEN-200 Enumeration and Reconnaissance Practice Question
While mapping a subnet you want to discover live hosts quickly before running detailed service scans. Which approach best fits an initial host-discovery sweep?
⚠ Common exam trap
The trap here is assuming ping alone identifies all live hosts, when many systems block ICMP yet still respond on TCP ports.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run an ICMP echo sweep combined with TCP SYN probes to common ports to identify responsive hosts.
Effective host discovery layers ICMP echo with TCP SYN probes to common ports, because many systems disable ping replies while still exposing services. This combination surfaces more live hosts faster than any single method, producing an accurate target list. Full port scans, single-port UDP probes, and ARP cache reads are either too slow, too unreliable, or too incomplete for an initial sweep.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Run an ICMP echo sweep combined with TCP SYN probes to common ports to identify responsive hosts.
Why this is correct
Combining ICMP echo with TCP SYN probes to frequently open ports catches hosts that block ping but still expose services, a common configuration. This layered discovery approach maximizes live-host detection quickly, providing a target list for later, more intensive service enumeration without wasting time scanning dead addresses.
- ✗
Query the local ARP cache and enumerate only the entries already present.
Why it's wrong here
The ARP cache only contains hosts you have recently communicated with, so it reflects prior activity rather than the full subnet. Using it alone yields a heavily incomplete picture and misses hosts never contacted, making it unsuitable as a primary discovery method during active network mapping.
- ✗
Send UDP probes to port 53 on every address and treat any reply as proof of a live host.
Why it's wrong here
UDP responses are unreliable indicators because most hosts do not run DNS or silently drop probes. Relying on a single UDP port misses the majority of live systems while producing many false negatives, making it a poor substitute for a layered ICMP and TCP discovery sweep across the subnet.
- ✗
Perform a full TCP connect scan of all ports against every address in the subnet range.
Why it's wrong here
Scanning all ports on every address is slow and noisy, consuming far more time than needed just to find live hosts. Host discovery exists to prune dead addresses first, so this approach inverts the efficient order of operations and burdens the network before you even know which systems respond.
Visual reference
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.