You must read Nmap output, pick the right scan flags, and explain port states. The key skill is matching the command to the objective: -sV for versions, -sU for UDP, -Pn to skip host discovery, and knowing open|filtered is ambiguous, not confirmed open.
Start practicing
Scanning and Host Discovery — choose a session length
Free · No account required
Domain overview
This domain covers Nmap-driven host discovery and port scanning: interpreting port states like open|filtered, selecting scan types (SYN, UDP, version detection), and sweeping subnets when ICMP is blocked. GPEN questions present scenarios with exhibits or command output and require you to choose correct Nmap syntax and explain scan behavior and limitations.
Exam objectives
Interpreting Nmap port states including open, closed, filtered, and open|filtered
Choosing Nmap flags such as -sV, -sU, -sS, and -Pn for specific goals
Performing host discovery sweeps with -sn when ICMP echo is blocked
Understanding UDP scan challenges: no handshake, ICMP rate limiting, slow results
Assuming open|filtered means the port is definitely open; it means Nmap cannot distinguish open from filtered, common with UDP or firewalled TCP.
Forgetting -sV when the question asks for exact service version; a plain port scan only reports the port state.
Using -sn for a sweep but expecting port results; -sn performs host discovery only and does not scan ports.
Click any question to see the full explanation and answer options, or start a focused practice session above.
You are performing a network audit and need to identify live hosts across a segmented network while minimizing the risk of triggering IDS alerts. Which Nmap technique is most appropriate for stealthy host discovery in a subnet where ICMP echo requests are filtered by the firewall?
2Refer to the exhibit. You executed an Nmap scan against a host and received the output shown. Which scanning technique was most likely used to produce this specific state-based output while avoiding the completion of a full TCP three-way handshake?
3You are analyzing a target environment and need to identify UDP services. Which THREE of the following are significant challenges associated with performing an accurate UDP scan compared to a TCP scan?
4Refer to the exhibit. What is the primary purpose of the Nmap Scripting Engine (NSE) in the context of the output provided, and how does it improve upon standard port scanning?
5When conducting a network scan, you notice that many hosts are not responding to ping requests, even though they are known to be online. What is the most appropriate Nmap flag to use to ensure these hosts are still scanned for open ports?
6Refer to the exhibit. What does the Nmap status 'open|filtered' indicate about the target port, and why does this result commonly occur in penetration testing scenarios?
7During an internal penetration test, you need to discover live hosts on a flat Layer 2 network segment. The client's IDS is known to alert on TCP SYN packets sent to closed ports. You want to minimize the chance of triggering an alert while still identifying as many hosts as possible. Which Nmap host discovery technique should you use?
8During an internal penetration test, you need to sweep a /24 subnet for live hosts using Nmap. The client's security team has confirmed that ICMP echo requests are blocked at the host firewall on all workstations, but they want you to use a technique that still elicits responses from hosts that are up without relying on ICMP. Which Nmap host discovery option should you use to maximize host detection in this environment?
9During an internal penetration test you need to enumerate live hosts on a /24 subnet that you suspect is protected by a stateful firewall dropping ICMP echo requests. You want the scan to be fast and you have administrative (root) privileges on your Kali system. Which Nmap command best accomplishes host discovery in this scenario?
10You are scanning a target that resides behind a firewall configured to drop TCP packets with the ACK flag set. You want to determine whether the firewall is stateful or stateless. Which Nmap scan type should you use to help make this determination by analyzing the responses to ACK packets?
11You are scanning a target from a host on the same Ethernet segment. You run 'nmap -sS -p 445 192.168.1.50' and receive a response indicating the port is open. You then run the same scan from a different subnet across a router and receive no response at all, even though the service is confirmed running. Which statement best explains this difference?
12You are performing a penetration test against a target that is behind a firewall configured to drop all TCP packets except those destined for port 443. You need to determine whether the firewall is stateful or stateless to plan your attack. Which Nmap scan technique will best help you make this determination?
13You are performing a penetration test against a web server that is protected by a network-based intrusion prevention system (IPS). You need to conduct a port scan while minimizing the chance of being blocked. Which two Nmap options should you use to evade the IPS? (Choose two.)
14You are performing a penetration test and need to scan a large Class B network (10.0.0.0/16) for live hosts. You want to minimize the scan time while still getting accurate results. Which Nmap option should you use to perform a ping sweep without port scanning?
15You are performing a penetration test and need to identify all live hosts on a subnet without performing a port scan. Which Nmap command should you use to accomplish this?
16You are performing a penetration test against a web server and want to identify the exact version of the HTTP service running on port 80. Which Nmap command should you use?
17You are scanning a target and need to avoid triggering a network IPS that signatures on TCP connect scans. You have root privileges and want to perform a stealthy scan that does not complete the TCP three-way handshake. Which Nmap scan type should you use?
You must read Nmap output, pick the right scan flags, and explain port states. The key skill is matching the command to the objective: -sV for versions, -sU for UDP, -Pn to skip host discovery, and knowing open|filtered is ambiguous, not confirmed open.
The Courseiva GPEN question bank contains 17 questions in the Scanning and Host Discovery domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Scanning and Host Discovery domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included