CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester needs to perform a comprehensive host discovery on an internal network segment (192.168.1.0/24) where ICMP echo requests might be blocked by firewalls or host-based security. To reliably identify live hosts even when ICMP is filtered, which Nmap command combination would be most effective?

  1. Anmap -sn -PU 53 192.168.1.0/24
  2. Bnmap -PE -PS -PA 192.168.1.0/24
  3. Cnmap -Pn 192.168.1.0/24
  4. Dnmap -sP 192.168.1.0/24
Show answer & explanation

Correct answer: A. nmap -sn -PU 53 192.168.1.0/24

The command `nmap -sn -PU 53 192.168.1.0/24` uses -sn for host discovery only (no port scan) and -PU 53 to send UDP probes to port 53. UDP probes are often effective for host discovery when ICMP is blocked, as many hosts respond to common UDP services.

Why the other options are wrong

  • B. `nmap -PE -PS -PA` sends ICMP echo, TCP SYN, and TCP ACK pings, but still relies on TCP/ICMP, which might be blocked. UDP probes are a good alternative.
  • C. `nmap -Pn` skips host discovery entirely and assumes all hosts are online, leading to full port scans of potentially non-existent hosts.
  • D. `nmap -sP` (or `-sn`) performs a ping scan, which primarily relies on ICMP echo requests and ARP, making it unreliable if ICMP is blocked.

Nmap UDP Host Discovery (-PU)

An Nmap technique for host discovery that sends UDP probes to common ports (e.g., 53, 161, 137) to elicit responses from live hosts, particularly effective when ICMP and TCP probes are blocked.

  • Uses UDP packets for host discovery.
  • Effective when ICMP and TCP pings are filtered.
  • Often targets common UDP ports like DNS (53) or SNMP (161).

Memory trick: When ICMP is a ghost, UDP probes can still find the host.

More Reconnaissance and Enumeration questions