20+ practice questions focused on Scanning and Mapping — one of the most tested topics on the GIAC Certified Incident Handler exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Scanning and Mapping PracticeAn incident responder needs to identify active hosts on a segmented network while minimizing the risk of triggering IDS alerts. Which Nmap technique is most appropriate for a stealthy discovery scan?
Explanation: TCP SYN scanning, often called half-open scanning, is the standard for stealthy host discovery because it never completes the TCP three-way handshake. By sending a SYN packet and waiting for a SYN/ACK, the scanner determines host status without establishing a full connection, which significantly reduces logged events on many application-layer logging systems and target service logs compared to full TCP connect scans.
When conducting network mapping, which TWO actions are considered best practice for ensuring the scan remains within the defined scope of an incident response engagement?
Explanation: Strict adherence to scope is critical to avoid legal and operational liability. Coordinating scan ranges with network administrators ensures that sensitive assets are not adversely impacted, and maintaining detailed logs of all traffic generated allows for post-incident review and validation that the responder only interacted with authorized subnets, thereby protecting the integrity of the professional engagement and preventing unauthorized disruption of enterprise infrastructure.
When mapping a network that employs egress filtering, which TWO scanning methodologies will likely produce inaccurate or incomplete results?
Explanation: Egress filtering limits the traffic leaving a network segment, meaning probes that rely on specific return packet types or source ports might be blocked. When responders use techniques that depend on non-standard responses or that are easily flagged by firewall rules, the lack of return traffic leads to an incomplete network map, effectively blinding the investigator to the true state of the internal environment.
An incident handler is performing an authorized network discovery on a segmented enterprise network and needs to identify active hosts without triggering aggressive firewall alarms. Which Nmap scanning technique best achieves stealthy host discovery while minimizing noise?
Explanation: TCP SYN ping scans send packets to ports like 80 or 443, effectively bypassing basic egress filtering and stateless packet inspection firewalls without establishing a full three-way handshake. This reduces log clutter and avoids generating application-layer connection events on target systems during initial reconnaissance phases.
An incident handler is tasked with auditing a corporate network for unauthorized live hosts without triggering aggressive firewall alarms or intrusion detection systems. Which Nmap scanning technique is best suited for discovering active hosts while minimizing the generation of traditional connection-state logs on stateful packet inspection firewalls?
Explanation: TCP ACK scanning sends packets with only the ACK flag set, which can bypass stateless firewalls and certain rule sets because they assume an established connection exists. While it cannot reliably determine open ports, it effectively maps live hosts by analyzing RST responses generated by hosts when receiving unexpected ACK packets.
+15 more Scanning and Mapping questions available
Practice all Scanning and Mapping questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Scanning and Mapping. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Scanning and Mapping questions on the GCIH frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Scanning and Mapping is tested as part of the GIAC Certified Incident Handler blueprint. Practicing with targeted Scanning and Mapping questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free GCIH practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Scanning and Mapping is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Scanning and Mapping practice session with instant scoring and detailed explanations.
Start Scanning and Mapping Practice →