You must plan scans against the signed scope, run Nmap UDP scans that distinguish open from filtered, configure least-privilege authenticated scans, and rank vulnerabilities by exploitability plus asset value. The single most important thing: never scan outside the authorized scope defined in the rules of engagement.
Start practicing
Vulnerability Scanning — choose a session length
Free · No account required
Domain overview
This domain covers planning, executing, and interpreting vulnerability scans within authorized engagements. GPEN tests your ability to scope scans via rules of engagement, configure authenticated scanning with least-privilege credentials, tune Nmap UDP scanning to resolve open|filtered ambiguity, and rank findings by exploitability and asset criticality rather than raw CVSS alone.
Exam objectives
Reading rules of engagement and scope documents before any scanning activity begins
Using Nmap UDP scans with version detection and timing options to classify open|filtered ports
Configuring authenticated Windows scans with least-privilege service or domain accounts
Prioritizing findings using CVSS, exploit availability, asset exposure, and business criticality
Scanning outside the authorized scope or before confirming rules of engagement, which invalidates the engagement regardless of findings
Treating open|filtered UDP results as confirmed open ports instead of retrying with version detection or ICMP responses
Using domain administrator credentials for authenticated scans when a limited read-only account would suffice
Click any question to see the full explanation and answer options, or start a focused practice session above.
A penetration tester is configuring an authenticated scan for a Windows environment. Which credential management strategy best minimizes the security impact while maintaining scan efficacy?
2Refer to the exhibit. An Nmap scan returns output indicating a web server is responding, but the `http-enum` script fails to identify common directories. Which action should the tester take to improve detection?
3What is the primary purpose of a 'delta' or 'differential' vulnerability scan?
4Which phase of a vulnerability assessment typically involves comparing the output against a known database of CVEs?
5Which of the following actions is the most appropriate step after discovering a critical vulnerability that is currently being exploited in the wild?
6Which document should a penetration tester consult to determine the allowed scope and rules of engagement for a vulnerability scan?
7A penetration tester is preparing to run a credentialed vulnerability scan against a mixed environment of Windows Server 2019 and Ubuntu 20.04 hosts on an internal /24 subnet. The tester wants to reduce scan duration and network load while still detecting missing patches and misconfigurations. Which two scanning techniques should the tester implement to achieve these goals? (Choose two.)
8During a vulnerability scan of a web application, the scanner reports a critical SQL injection vulnerability on a login form. A manual test using a single quote in the username field returns a generic error page with no database details. The scanner's evidence shows a time-based blind SQL injection payload that caused a five-second delay. Which action should the penetration tester take next to validate the finding?
9A penetration tester is using Nessus to scan a large subnet and needs to avoid overwhelming older printers that are known to crash when too many simultaneous connections are made. The tester also wants to ensure the scan completes in a reasonable timeframe. Which Nessus scan policy setting should be adjusted to control the number of simultaneous hosts being scanned?
10A penetration tester is configuring a vulnerability scanner to assess a sensitive production network. The tester wants to avoid causing service disruptions or overwhelming network devices. Which scanner setting should be adjusted to best achieve this?
11During a penetration test, a tester runs an OpenVAS scan against a web server and receives a report indicating a high-severity vulnerability with a CVE identifier. Before including it in the final report, the tester wants to verify if the vulnerability is actually exploitable. Which action should the tester take next?
12A penetration tester is analyzing the results of a vulnerability scan and needs to prioritize remediation efforts. Which two factors should be considered when determining the criticality of a vulnerability? (Choose two.)
13A penetration tester is using Nmap to scan a target network and wants to identify open UDP ports. The tester runs a UDP scan but notices that many ports are reported as 'open|filtered'. Which technique can help determine whether these ports are actually open or filtered?
14A penetration tester needs to scan a large enterprise network for vulnerabilities but has only a short maintenance window. The tester wants to maximize scan coverage while minimizing the impact on production systems. Which Nessus scan policy setting should the tester adjust to balance speed and accuracy?
15A penetration tester is using Nmap to scan a target subnet and wants to identify all hosts that are up without performing port scanning. The tester also wants to avoid sending TCP SYN packets to reduce noise. Which Nmap option should the tester use?
16A penetration tester is conducting a vulnerability scan against a web application and notices that the scanner reports a critical SQL injection vulnerability on a page that does not accept user input. The tester manually verifies the page and finds no input fields or parameters. What is the most likely cause of this false positive?
17A penetration tester is planning a vulnerability scan of a network that includes legacy systems and IoT devices. The tester needs to minimize the risk of disrupting these fragile devices while still gathering useful vulnerability data. Which two actions should the tester take? (Choose two.)
18A penetration tester is configuring a vulnerability scan against a large enterprise network. The tester needs to balance scan accuracy, speed, and impact on production systems. Which TWO of the following settings, when adjusted, will MOST directly reduce the risk of disrupting fragile network devices during the scan? (Choose two.)
19A penetration tester is reviewing the results of a vulnerability scan and sees a finding labeled 'SSL Certificate Expired' on a web server. The tester confirms that the certificate is indeed expired. What is the most appropriate next step according to typical penetration testing methodology?
20A penetration tester has completed an unauthenticated vulnerability scan of a web server and received a report listing several critical CVEs. Before including these in the final report, the tester wants to validate that the findings are not false positives. Which action is the MOST appropriate next step?
21A penetration tester is using Nmap with the NSE script 'vulners' to identify vulnerabilities on a target. The scan returns a list of CVEs for detected services, but the tester notices that some CVEs have a low confidence score. What is the MOST accurate interpretation of these low-confidence findings?
22A penetration tester is preparing to scan a network that includes a mix of traditional IT systems and industrial control systems (ICS). The tester wants to minimize the risk of disrupting ICS devices. Which scanning approach is MOST appropriate for the ICS segment?
You must plan scans against the signed scope, run Nmap UDP scans that distinguish open from filtered, configure least-privilege authenticated scans, and rank vulnerabilities by exploitability plus asset value. The single most important thing: never scan outside the authorized scope defined in the rules of engagement.
The Courseiva GPEN question bank contains 22 questions in the Vulnerability Scanning domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Vulnerability Scanning domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included