EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesHard

A security auditor is performing an external penetration test and wants to identify live hosts on the target's network segment without generating excessive network traffic that might trigger intrusion detection systems. The target network is known to filter ICMP echo requests. Which of the following Nmap host discovery techniques would be most effective and stealthy in this scenario?

  1. ANmap -PS <port> (TCP SYN ping) or -PA <port> (TCP ACK ping) to common open ports.
  2. BNmap -Pn (No ping) with a full TCP connect scan (-sT).
  3. CNmap -sn (Ping scan) using default ICMP echo requests.
  4. DNmap -PE -PP -PM (ICMP echo, timestamp, netmask requests).
Show answer & explanation

Correct answer: A. Nmap -PS <port> (TCP SYN ping) or -PA <port> (TCP ACK ping) to common open ports.

Since ICMP is filtered, traditional ping scans are ineffective. TCP SYN ping (-PS) or TCP ACK ping (-PA) probes specific (likely open) TCP ports. This method attempts to elicit a TCP response (SYN/ACK or RST) indicating a live host, making it more reliable and stealthier than a full connect scan or relying on filtered ICMP.

Why the other options are wrong

  • B. While -Pn bypasses host discovery, combining it with a full TCP connect scan (-sT) is very noisy and intrusive, likely triggering IDS, and doesn't solve the host discovery problem stealthily.
  • C. Using default ICMP echo requests (-sn) will be ineffective as the target is known to filter ICMP.
  • D. These options also rely on various forms of ICMP, which are known to be filtered, making them ineffective.

Nmap Host Discovery (TCP Ping)

Nmap's TCP ping (SYN or ACK scan) is a host discovery technique that sends TCP packets to specified ports on target hosts to determine if they are live, especially useful when ICMP is blocked.

  • `-PS` sends a SYN packet; `-PA` sends an ACK packet.
  • A SYN/ACK response (for -PS) or RST response (for -PA) indicates a live host.
  • More stealthy than a full port scan for host discovery.
  • Requires specifying common open ports (e.g., 80, 443, 22) for best results.

Memory trick: Ping for life, but if ICMP sleeps, use TCP to peek.

More Reconnaissance Techniques questions