EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesMedium
An ethical hacker is performing an internal penetration test. They have gained access to a workstation on a subnet and want to quickly identify other active hosts on the *same local subnet* without routing through any Layer 3 devices. Which Nmap host discovery technique is most efficient for this specific scenario?
- AARP Ping Scan (-PR)
- BUDP Ping Scan (-PU)
- CICMP Echo Ping Scan (-PE)
- DTCP SYN Ping Scan (-PS)
Show answer & explanationAnswer & explanation
Correct answer: A. ARP Ping Scan (-PR)
ARP (Address Resolution Protocol) Ping Scan (-PR) operates at Layer 2 (Data Link Layer) and is highly effective for discovering live hosts on the local subnet. It sends ARP requests and listens for ARP replies, bypassing any Layer 3 firewall rules that might block ICMP or TCP/UDP probes.
Why the other options are wrong
- B. UDP Ping Scan operates at Layer 3/4 and is less efficient and reliable for simple host discovery on a local subnet than ARP.
- C. ICMP Echo Ping Scan operates at Layer 3 and can be blocked by host-based firewalls or network devices, and still involves IP addressing/routing.
- D. TCP SYN Ping Scan operates at Layer 3/4 and would involve IP routing, which is not ideal for 'same local subnet' and 'without routing'.
ARP Ping Scan (-PR)
An Nmap host discovery method that uses ARP requests to find live hosts on a local Ethernet network. It's very fast and effective for local subnet scanning as it operates at Layer 2.
- Operates at Layer 2 (Data Link)
- Sends ARP requests, listens for ARP replies
- Only works on local subnet
- Bypasses most Layer 3 firewall rules
Memory trick: ARP is like shouting 'who's here?' on your street.