CompTIA PenTest+ (PT0-003)Attacks and ExploitsEasy
A penetration tester is performing a network reconnaissance using Nmap. They need to quickly identify all active hosts within the 192.168.1.0/24 subnet without performing a full port scan on each host. Which Nmap command option should they use?
- Anmap -p 1-65535 192.168.1.0/24
- Bnmap -O 192.168.1.0/24
- Cnmap -sn 192.168.1.0/24
- Dnmap -sS 192.168.1.0/24
Show answer & explanationAnswer & explanation
Correct answer: C. nmap -sn 192.168.1.0/24
The `nmap -sn` command (previously `-sP`) performs a 'ping scan' or 'host discovery' scan. It identifies active hosts on a network without performing a port scan, making it ideal for quickly finding live systems.
Why the other options are wrong
- A. `-p 1-65535` specifies a full port scan of all ports, which is explicitly what the tester wants to avoid.
- B. `-O` attempts OS detection, which happens after host discovery and involves port scanning.
- D. `-sS` performs a SYN stealth scan, which is a full port scan type, not just host discovery.
Nmap Host Discovery (-sn)
An Nmap scan type that quickly identifies active hosts on a network by sending various probes (ICMP echo requests, TCP SYN to common ports, ARP requests) without performing a full port scan on each discovered host.
- Also known as 'ping scan'.
- Uses diverse methods to detect live hosts.
- Much faster than full port scanning for large networks.
- Does not determine open ports or services.
Memory trick: Scan for Nothin' (-sn) if you just want to see who's there.