EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesMedium

An ethical hacker is performing an internal penetration test. They have gained access to a workstation on a subnet and want to quickly identify other active hosts on the *same local subnet* without routing through any Layer 3 devices. Which Nmap host discovery technique is most efficient for this specific scenario?

  1. AARP Ping Scan (-PR)
  2. BUDP Ping Scan (-PU)
  3. CICMP Echo Ping Scan (-PE)
  4. DTCP SYN Ping Scan (-PS)
Show answer & explanation

Correct answer: A. ARP Ping Scan (-PR)

ARP (Address Resolution Protocol) Ping Scan (-PR) operates at Layer 2 (Data Link Layer) and is highly effective for discovering live hosts on the local subnet. It sends ARP requests and listens for ARP replies, bypassing any Layer 3 firewall rules that might block ICMP or TCP/UDP probes.

Why the other options are wrong

  • B. UDP Ping Scan operates at Layer 3/4 and is less efficient and reliable for simple host discovery on a local subnet than ARP.
  • C. ICMP Echo Ping Scan operates at Layer 3 and can be blocked by host-based firewalls or network devices, and still involves IP addressing/routing.
  • D. TCP SYN Ping Scan operates at Layer 3/4 and would involve IP routing, which is not ideal for 'same local subnet' and 'without routing'.

ARP Ping Scan (-PR)

An Nmap host discovery method that uses ARP requests to find live hosts on a local Ethernet network. It's very fast and effective for local subnet scanning as it operates at Layer 2.

  • Operates at Layer 2 (Data Link)
  • Sends ARP requests, listens for ARP replies
  • Only works on local subnet
  • Bypasses most Layer 3 firewall rules

Memory trick: ARP is like shouting 'who's here?' on your street.

More Reconnaissance Techniques questions