CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester is performing an internal network assessment. They have compromised a Windows workstation and want to quickly identify other active hosts on the local subnet without triggering excessive alerts. Which command-line tool and technique would be MOST appropriate for a quick, low-impact host discovery?

  1. Aping -t <subnet_address>
  2. Bnetstat -ano
  3. Cfor /L %i in (1,1,254) do @ping -n 1 192.168.1.%i | findstr "Reply"
  4. Dnmap -sn <subnet_address>/24
Show answer & explanation

Correct answer: C. for /L %i in (1,1,254) do @ping -n 1 192.168.1.%i | findstr "Reply"

Using a 'for' loop with 'ping -n 1' on Windows allows the tester to send a single ICMP echo request to each IP address in the subnet, and 'findstr "Reply"' filters for active hosts. This is a common, built-in method for quick host discovery on Windows with minimal footprint.

Why the other options are wrong

  • A. The '-t' flag pings indefinitely, which is not suitable for a quick scan and can be noisy.
  • B. This command lists active network connections and listening ports on the local machine, not other hosts on the subnet.
  • D. Nmap is an external tool and might not be available or permitted on a compromised internal workstation; also, '-sn' (ping scan) can still be detected.

Windows Ping Sweep

A technique using the built-in 'ping' command within a 'for' loop on a Windows system to send ICMP echo requests to a range of IP addresses, identifying active hosts on a local subnet.

  • Uses native Windows tools (ping, for loop).
  • Identifies active hosts via ICMP replies.
  • Low-impact and less likely to trigger alerts than dedicated scanners.

Memory trick: For every IP, ping once to find the active ones.

More Reconnaissance and Enumeration questions