EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesMedium

A penetration tester is evaluating the security posture of an organization's internal network. They want to identify active hosts on the local subnet without generating significant network traffic that could trigger intrusion detection systems. Which Nmap scan type is best suited for this objective?

  1. ANmap -sS (TCP SYN Scan)
  2. BNmap -sV (Service Version Detection)
  3. CNmap -sn (Ping Scan / Host Discovery)
  4. DNmap -sU (UDP Scan)
Show answer & explanation

Correct answer: C. Nmap -sn (Ping Scan / Host Discovery)

The Nmap -sn (or -sP in older versions) option performs a 'Ping Scan' or 'Host Discovery' scan. It's designed to identify active hosts on a network without performing port scans, thus generating less traffic and being less intrusive than a full port scan or service version detection.

Why the other options are wrong

  • A. TCP SYN Scan attempts to establish a connection to each port, generating more traffic and potentially triggering IDS.
  • B. Service Version Detection (-sV) is highly intrusive and generates significant traffic as it tries to determine the exact version of services running on open ports.
  • D. UDP Scan sends UDP packets to common ports, also generating more traffic than a simple host discovery and being slower.

Nmap Ping Scan (-sn)

An Nmap scan type focused solely on host discovery, determining which hosts on a network are online without performing port scanning.

  • Uses ICMP echo requests, TCP SYN to 443, and TCP ACK to 80 by default.
  • Generates less traffic than full port scans.
  • Useful for identifying live hosts without being overly intrusive.

Memory trick: Ping Scan: 'Are you there? Just a quick hello, no need to open the door!'

More Reconnaissance Techniques questions