CompTIA PenTest+ (PT0-003)Attacks and ExploitsEasy

A tester needs to quickly determine which hosts are online across a 254-address subnet before running detailed service scans, without sending any TCP/UDP port probes to the targets. Which nmap command should the tester run?

  1. Anmap -sn 192.168.1.0/24
  2. Bnmap -sV 192.168.1.0/24
  3. Cnmap -A 192.168.1.0/24
  4. Dnmap -sS 192.168.1.0/24
Show answer & explanation

Correct answer: A. nmap -sn 192.168.1.0/24

The -sn flag performs a host discovery (ping) scan and disables port scanning entirely, making it ideal for quickly identifying live hosts. -sS, -sV, and -A all involve port scanning and are slower/more intrusive.

Why the other options are wrong

  • B. -sV performs version detection, which requires open ports and probes.
  • C. -A enables aggressive scanning including OS detection, scripts, and version scanning.
  • D. -sS performs a SYN port scan, which is a full port probe, not just discovery.

nmap Host Discovery (-sn)

An nmap scan mode that identifies live hosts on a network using ICMP, ARP, or TCP/UDP probes without scanning any ports.

  • -sn = 'no port scan', formerly called -sP
  • Useful for fast network sweeps before deeper scans
  • Falls back to ARP requests on local subnets for speed

Memory trick: 'sn' = Scan Nothing but hosts

More Attacks and Exploits questions