CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationHard
A penetration tester is performing post-exploitation on a compromised Linux server within a client's internal network. They need to identify other active hosts on the local subnet to expand their foothold, but they want to avoid using traditional active scanning tools like Nmap directly from the compromised host to minimize detection. Which of the following methods could potentially achieve this goal passively or semi-passively?
- AChecking the ARP cache (`arp -a`) on the compromised host.
- BPerforming a full TCP connect scan (`nmap -sT <subnet>`).
- CExecuting a Metasploit auxiliary scanner module for the local subnet.
- DRunning `nmap -sn -PE -PA <subnet>` from the compromised host.
Show answer & explanationAnswer & explanation
Correct answer: A. Checking the ARP cache (`arp -a`) on the compromised host.
Checking the ARP cache (`arp -a` on Linux/Windows) on the compromised host is a semi-passive method. It reveals IP-to-MAC address mappings of other devices that the compromised host has recently communicated with, without sending new, potentially detectable, network traffic for discovery.
Why the other options are wrong
- B. A full TCP connect scan is a very active and noisy method that would significantly increase the risk of detection.
- C. Metasploit auxiliary scanners are active scanning tools that generate network traffic, similar to Nmap, and would likely trigger alerts.
- D. Running Nmap with `-sn` (no port scan) still sends active probes (ICMP echo, TCP SYN to 443/80, ARP requests) which can be detected.
ARP Cache for Reconnaissance
The Address Resolution Protocol (ARP) cache stores IP-to-MAC address mappings of recently communicated devices on a local network segment, which can be inspected for passive host discovery.
- Provides information about directly connected devices.
- Does not generate new network traffic for discovery.
- Limited to devices the host has recently interacted with.
Memory trick: Internal recon: ARP cache quiet, Nmap loud, Metasploit active.