CompTIA CySA+ (CS0-003)Vulnerability ManagementEasy
A network administrator runs an Nmap SYN scan across the 10.1.5.0/24 subnet, sending probe packets directly to each address to identify live hosts, open ports, and service versions for an updated asset inventory. Which asset discovery technique does this describe?
- AActive discovery
- BPassive discovery
- CNetFlow analysis
- DAgent-based discovery
Show answer & explanationAnswer & explanation
Correct answer: A. Active discovery
Active discovery involves sending probe packets (pings, SYN packets, port scans) directly to hosts to enumerate devices and services, unlike passive discovery which only observes existing traffic.
Why the other options are wrong
- B. Passive discovery only listens to existing network traffic without sending probes.
- C. NetFlow analysis reviews flow metadata collected by network devices, not direct probing.
- D. Agent-based discovery relies on software installed on each endpoint, not network probes.
Active Asset Discovery
A discovery method that sends probe traffic (ping sweeps, port scans) directly to hosts to identify live systems and services.
- Uses tools like Nmap, Masscan
- Generates network traffic that can be detected by IDS
- More thorough than passive but can disrupt fragile systems like ICS
Memory trick: PAAL: Passive listens, Active probes, Agent installs, Logs correlate.