CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium
A penetration tester is performing an internal network assessment. They have compromised a Linux workstation and want to identify other active hosts on the local subnet without generating excessive network traffic that might alert administrators. Which command-line tool and option combination is most appropriate for a quick and relatively quiet host discovery on a Linux system?
- Aping -c 1 -t 255 <target_ip>
- Barp -a
- Cnmap -sn <target_subnet>
- Dnetstat -tulnp
Show answer & explanationAnswer & explanation
Correct answer: C. nmap -sn <target_subnet>
The `nmap -sn` command performs a 'ping scan' (host discovery only) without port scanning. It sends ICMP echo requests, TCP SYN to port 443, and TCP ACK to port 80, along with an ARP request for local targets, providing a relatively quick and effective way to identify active hosts on a subnet with minimal noise compared to a full port scan.
Why the other options are wrong
- A. This `ping` command is for a single host and uses a TTL of 255, not for subnet host discovery. A broadcast ping could be noisy.
- B. `arp -a` shows the ARP cache, which only lists hosts the system has recently communicated with, not all active hosts on the subnet.
- D. `netstat -tulnp` lists open ports and listening services on the local machine, not other hosts on the network.
Nmap Host Discovery (-sn)
The `nmap -sn` (or `--ping-scan`) command is used to perform host discovery without port scanning. It sends various probes (ICMP echo request, TCP SYN to 443, TCP ACK to 80, ARP request for local targets) to determine which hosts are active on a network.
- Does not perform port scanning.
- Identifies active (live) hosts.
- Uses a combination of ICMP, TCP, and ARP probes.
- Often quicker and less noisy than a full scan.
Memory trick: Nmap's 'sn' (silent network) finds hosts without making a racket.