EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesMedium

An ethical hacker is performing an internal penetration test and has gained access to a workstation. They want to identify other active hosts on the local network segment without sending any packets that would leave the local subnet and trigger network-based intrusion detection systems (NIDS). Which of the following Nmap host discovery techniques would be most suitable for this scenario?

  1. AUDP Ping (-PU)
  2. BARP Ping (-PR)
  3. CTCP SYN Ping (-PS)
  4. DICMP Echo Ping (-PE)
Show answer & explanation

Correct answer: B. ARP Ping (-PR)

ARP Ping (-PR) uses ARP requests to discover hosts on the local network segment. ARP traffic does not traverse routers, making it ideal for host discovery within a local subnet without sending packets that would leave the local network and potentially trigger NIDS.

Why the other options are wrong

  • A. UDP Ping sends UDP packets to common ports, which can cross subnets and may trigger NIDS.
  • C. TCP SYN Ping sends TCP SYN packets, which can cross subnets if routing allows and may trigger NIDS.
  • D. ICMP Echo Ping sends ICMP packets, which can cross subnets and are commonly monitored by NIDS.

Nmap ARP Ping (-PR)

An Nmap host discovery method that sends ARP requests to identify live hosts on a local Ethernet network. It operates at Layer 2 and does not traverse routers.

  • Operates at Layer 2 (Data Link Layer).
  • Does not cross subnet boundaries.
  • Effective for local network host discovery.
  • Less likely to trigger NIDS compared to Layer 3 pings.

Memory trick: Pings are like knocking; ARP is like asking your neighbor directly.

More Reconnaissance Techniques questions