CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester is performing an internal network assessment and has gained access to a Windows workstation. They need to quickly identify other active hosts on the local subnet without installing any new tools or generating excessive network traffic that might trigger alerts. Which native Windows command-line utility is best suited for this task?

  1. Atracert <hostname>
  2. Bping -n 1 -w 100 <IPRange>
  3. Cnetstat -ano
  4. Dipconfig /all
Show answer & explanation

Correct answer: B. ping -n 1 -w 100 <IPRange>

The 'ping' command can be used to perform a rudimentary host discovery by sending ICMP echo requests to a range of IP addresses. The '-n 1' option sends a single packet, and '-w 100' sets a short timeout of 100ms, minimizing traffic and time while identifying active hosts that respond.

Why the other options are wrong

  • A. tracert maps the network path to a specific host, not for discovering multiple hosts on a subnet.
  • C. netstat -ano shows active connections and listening ports on the local machine, not other hosts.
  • D. ipconfig /all displays network configuration details for the local machine, not other hosts.

Windows Ping Sweep

Using the native 'ping' command in Windows to send ICMP echo requests to a range of IP addresses to identify active hosts on a network segment.

  • Uses ICMP echo requests.
  • Native Windows utility.
  • Identifies active hosts (those that respond).
  • Can be configured for single packets and short timeouts to reduce traffic.

Memory trick: PINGing for Friends on the Network

More Reconnaissance and Enumeration questions