Courseiva

PEN-200 Enumeration and Reconnaissance Practice Question

While mapping a subnet you want to discover live hosts quickly before running detailed service scans. Which approach best fits an initial host-discovery sweep?

⚠ Common exam trap

The trap here is assuming ping alone identifies all live hosts, when many systems block ICMP yet still respond on TCP ports.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run an ICMP echo sweep combined with TCP SYN probes to common ports to identify responsive hosts.

Effective host discovery layers ICMP echo with TCP SYN probes to common ports, because many systems disable ping replies while still exposing services. This combination surfaces more live hosts faster than any single method, producing an accurate target list. Full port scans, single-port UDP probes, and ARP cache reads are either too slow, too unreliable, or too incomplete for an initial sweep.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Run an ICMP echo sweep combined with TCP SYN probes to common ports to identify responsive hosts.

    Why this is correct

    Combining ICMP echo with TCP SYN probes to frequently open ports catches hosts that block ping but still expose services, a common configuration. This layered discovery approach maximizes live-host detection quickly, providing a target list for later, more intensive service enumeration without wasting time scanning dead addresses.

  • ✗

    Query the local ARP cache and enumerate only the entries already present.

    Why it's wrong here

    The ARP cache only contains hosts you have recently communicated with, so it reflects prior activity rather than the full subnet. Using it alone yields a heavily incomplete picture and misses hosts never contacted, making it unsuitable as a primary discovery method during active network mapping.

  • ✗

    Send UDP probes to port 53 on every address and treat any reply as proof of a live host.

    Why it's wrong here

    UDP responses are unreliable indicators because most hosts do not run DNS or silently drop probes. Relying on a single UDP port misses the majority of live systems while producing many false negatives, making it a poor substitute for a layered ICMP and TCP discovery sweep across the subnet.

  • ✗

    Perform a full TCP connect scan of all ports against every address in the subnet range.

    Why it's wrong here

    Scanning all ports on every address is slow and noisy, consuming far more time than needed just to find live hosts. Host discovery exists to prune dead addresses first, so this approach inverts the efficient order of operations and burdens the network before you even know which systems respond.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.