nerdexam
EC-Council

312-50V13 · Question #622

An ethical hacker is preparing to scan a network to identify live systems. To increase the efficiency and accuracy of his scans, he is considering several different host discovery techniques. He…

The correct answer is D. ARP Ping Scan. To effectively identify live systems on a LAN with restrictive firewalls and many unused IP addresses, an ARP ping scan is the most effective host discovery technique.

Submitted by ricky.ec· Mar 6, 2026Scanning Networks

Question

An ethical hacker is preparing to scan a network to identify live systems. To increase the efficiency and accuracy of his scans, he is considering several different host discovery techniques. He expects several unused IP addresses at any given time, specifically within the private address range of the LAN, but he also anticipates the presence of restrictive firewalls that may conceal active devices. Which scanning method would be most effective in this situation?

Options

  • AICMP ECHO Ping Sweep
  • BICMP Timestamp Ping
  • CTCP SYN Ping
  • DARP Ping Scan

How the community answered

(42 responses)
  • A
    10% (4)
  • B
    33% (14)
  • C
    14% (6)
  • D
    43% (18)

Why each option

To effectively identify live systems on a LAN with restrictive firewalls and many unused IP addresses, an ARP ping scan is the most effective host discovery technique.

AICMP ECHO Ping Sweep

ICMP ECHO ping sweeps are often blocked by restrictive firewalls, making them ineffective for discovering live hosts behind such firewalls.

BICMP Timestamp Ping

ICMP Timestamp pings are also a type of ICMP request and are susceptible to being blocked by restrictive firewalls, similar to ICMP ECHO.

CTCP SYN Ping

TCP SYN pings work at Layer 3/4 and can be blocked by stateful firewalls, especially if they are configured to drop unsolicited SYN packets or deny access to common ports.

DARP Ping ScanCorrect

An ARP (Address Resolution Protocol) ping scan works at Layer 2 within the local network segment, bypassing many restrictive firewalls that operate at Layer 3 or higher. Since it directly queries for MAC addresses corresponding to IP addresses on the local LAN, it is highly accurate for discovering active hosts within the private address range, even with unused IPs or blocked ICMP/TCP traffic.

Concept tested: Host discovery on LAN with restrictive firewalls

Source: https://nmap.org/book/host-discovery-arp-scan.html

Topics

#host discovery#network scanning#ARP ping scan#firewall evasion

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice