exam questions

Exam 312-50v12 All Questions

View all questions & answers for the 312-50v12 exam

Exam 312-50v12 topic 1 question 224 discussion

Actual exam question from ECCouncil's 312-50v12
Question #: 224
Topic #: 1
[All 312-50v12 Questions]

An ethical hacker is preparing to scan a network to identify live systems. To increase the efficiency and accuracy of his scans, he is considering several different host discovery techniques. He expects several unused IP addresses at any given time, specifically within the private address range of the LAN, but he also anticipates the presence of restrictive firewalls that may conceal active devices. Which scanning method would be most effective in this situation?

  • A. ICMP ECHO Ping Sweep
  • B. ICMP Timestamp Ping
  • C. TCP SYN Ping
  • D. ARP Ping Scan
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Mos3ab
5 days, 3 hours ago
Selected Answer: D
Address Resolution Protocol (ARP) is fundamental to network communication within a LAN. It maps IP addresses to MAC addresses, enabling devices to locate each other on the same subnet. Since ARP operates at the Data Link Layer (Layer 2) of the OSI model, its requests and responses are not typically filtered by firewalls, which usually operate at higher layers. Therefore, ARP scans can effectively identify active devices on a local network, even if those devices have firewalls that block ICMP or TCP probes. Tools like Nmap utilize ARP requests for host discovery on local networks. When scanning a local subnet, Nmap automatically employs ARP requests to detect live hosts, as this method is both reliable and efficient in a LAN environment. For example, executing nmap -sn -PR 192.168.1.0/24 will perform an ARP ping scan across the specified subnet, quickly identifying active devices.
upvoted 2 times
...
sumanroy
1 month, 3 weeks ago
Selected Answer: D
ARP is not blocked by firewalls
upvoted 1 times
...
g_man_rap
3 months, 3 weeks ago
D. ARP Ping Scan ARP (Address Resolution Protocol) Ping is used to resolve IP addresses to MAC addresses within the same broadcast domain (local network). Since ARP does not traverse routers and is not blocked by firewalls within the local network, it provides a reliable method for discovering hosts on the local subnet, even if they are configured to block ICMP and TCP/IP traffic.
upvoted 1 times
...
qtygbapjpesdayazko
5 months, 1 week ago
Selected Answer: D
Is D, arp scan. Keyword "private address range of the LAN".
upvoted 1 times
...
brrbrr
6 months ago
Selected Answer: C
TCP SYN Ping (C): This method sends TCP SYN packets to specific ports. It is more stealthy than ICMP-based methods and can bypass firewalls. If a device responds with a SYN-ACK, it indicates the device is active.
upvoted 1 times
brrbrr
6 months ago
actually, D is the correct answer. The presence of the keyword LAN indicates that the ethical hacker performs his testing on LAN, thus ARP Ping Scan is the more convenient scanning technique here.
upvoted 3 times
...
...
insaniunt
6 months, 1 week ago
Selected Answer: D
D. ARP Ping Scan
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago