CompTIA PenTest+ (PT0-003)Attacks and ExploitsEasy

A penetration tester is performing a network reconnaissance using Nmap. They need to quickly identify all active hosts within the 192.168.1.0/24 subnet without performing a full port scan on each host. Which Nmap command option should they use?

  1. Anmap -p 1-65535 192.168.1.0/24
  2. Bnmap -O 192.168.1.0/24
  3. Cnmap -sn 192.168.1.0/24
  4. Dnmap -sS 192.168.1.0/24
Show answer & explanation

Correct answer: C. nmap -sn 192.168.1.0/24

The `nmap -sn` command (previously `-sP`) performs a 'ping scan' or 'host discovery' scan. It identifies active hosts on a network without performing a port scan, making it ideal for quickly finding live systems.

Why the other options are wrong

  • A. `-p 1-65535` specifies a full port scan of all ports, which is explicitly what the tester wants to avoid.
  • B. `-O` attempts OS detection, which happens after host discovery and involves port scanning.
  • D. `-sS` performs a SYN stealth scan, which is a full port scan type, not just host discovery.

Nmap Host Discovery (-sn)

An Nmap scan type that quickly identifies active hosts on a network by sending various probes (ICMP echo requests, TCP SYN to common ports, ARP requests) without performing a full port scan on each discovered host.

  • Also known as 'ping scan'.
  • Uses diverse methods to detect live hosts.
  • Much faster than full port scanning for large networks.
  • Does not determine open ports or services.

Memory trick: Scan for Nothin' (-sn) if you just want to see who's there.

More Attacks and Exploits questions