CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationEasy
A penetration tester is performing external reconnaissance against a client's network. They have identified several public IP addresses and want to quickly determine if any hosts are online without performing deep port scans or generating significant traffic. They need a fast and basic host discovery method. Which Nmap command is most appropriate for this initial stage?
- Anmap -O <target_IP_range>
- Bnmap -sV <target_IP_range>
- Cnmap -sn <target_IP_range>
- Dnmap -p- <target_IP_range>
Show answer & explanationAnswer & explanation
Correct answer: C. nmap -sn <target_IP_range>
The `nmap -sn` command (previously `-sP`) performs a 'ping scan' or 'host discovery scan'. It sends ICMP echo requests, TCP SYN packets to port 443, TCP ACK packets to port 80, and an ICMP timestamp request to determine if a host is online, without scanning any ports. This is fast and generates minimal traffic.
Why the other options are wrong
- A. -O performs OS detection, which is also a deep scan and generates more traffic than simple host discovery.
- B. -sV performs service version detection, which is a deep scan and generates significant traffic, not suitable for quick host discovery.
- D. -p- scans all 65535 ports, which is an extremely deep and time-consuming scan, not suitable for quick host discovery.
Nmap Host Discovery (-sn)
Nmap's 'ping scan' or 'host discovery scan' (`-sn` or `--ping-scan`) is used to quickly determine which hosts on a network are online without performing a full port scan.
- Does not scan ports.
- Sends ICMP echo requests, TCP SYN/ACK, ICMP timestamp.
- Fast and low-traffic.
- Identifies active hosts.
Memory trick: SNiff Out Neighbors Fast