Be able to configure and troubleshoot authenticated scans, pick the right Nmap scan type, and choose an open-source scanner. The key is matching scan method to target: authenticated scans need working credentials and correct protocol settings, while local enumeration catches what remote scans miss.
Start practicing
Vulnerability Scanning and Penetration Testing — choose a session length
Free · No account required
Domain overview
This GSEC domain covers finding and validating weaknesses through vulnerability scanning and penetration testing. Expect questions on authenticated versus unauthenticated scanning, scanner configuration, credential and protocol issues, Nmap scan selection, open-source tooling, and post-exploitation local enumeration to catch gaps remote scans miss.
Exam objectives
Configuring authenticated SSH scans on Linux and troubleshooting scanner login failures
Choosing Nmap scan types for authenticated Windows scanning with domain admin rights
Selecting open-source, maintained vulnerability scanners for subnet-wide assessments
Using local enumeration on a compromised host to find missing patches and misconfigurations
Assuming valid credentials guarantee scanner login; SSH key format, sudo restrictions, or shell settings can break authenticated scans.
Confusing Nmap service/version detection with authenticated vulnerability scanning; Nmap alone does not log in and audit patches.
Trusting a single unauthenticated remote scan as complete, missing local-only patch and configuration issues exposed after a shell.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A security analyst is preparing to run an authenticated vulnerability scan against a Windows Server 2019 host. The analyst has domain credentials with local administrator rights on the target. Which Nmap scan type should the analyst use to perform a full TCP connect scan without requiring raw packet privileges?
2A junior security analyst at a healthcare company must scan a subnet of 254 hosts for known vulnerabilities. The analyst has no budget for commercial tools and needs a scanner that is open source, actively maintained, and capable of authenticated and unauthenticated checks. Which tool BEST meets these requirements?
3During an authorized penetration test, a tester obtains a low-privilege shell on a Windows server and wants to identify missing patches and insecure configurations that a remote unauthenticated scan may have missed. Which action BEST supports this goal?
4A security consultant is configuring a Tenable Nessus scan to assess a mixed environment of Windows and Linux servers. The consultant needs to ensure the scan can authenticate to targets and perform local checks without relying on agent installation. Which two Nessus scan settings should the consultant configure to provide credentials for authenticated scanning? (Choose two.)
5A security team is configuring an authenticated vulnerability scan of a Linux server farm using SSH. The scanner reports that it cannot log in to several hosts even though the same credentials work manually. Which configuration change is MOST likely to resolve the issue?
6A penetration tester is planning a web application assessment for a client. The tester wants to combine automated scanning with manual techniques to maximize coverage. Which two actions are MOST appropriate to include in the plan? (Choose two.)
7A vulnerability scan of a production web server reports a critical remote code execution vulnerability, but the system administrator insists the server is fully patched. The scanner used only unauthenticated checks. Which step should the security analyst take FIRST to resolve the discrepancy?
8A penetration tester is preparing an authorized internal assessment and must decide how to handle the discovery phase before running exploitation attempts. The client's rules of engagement permit scanning but forbid any action that could cause a denial of service on production hosts. The tester's goal is to map live hosts, open ports, and service versions with minimal impact while still gathering enough data to plan later exploitation. Which approach best satisfies both the engagement constraints and the assessment objective?
Be able to configure and troubleshoot authenticated scans, pick the right Nmap scan type, and choose an open-source scanner. The key is matching scan method to target: authenticated scans need working credentials and correct protocol settings, while local enumeration catches what remote scans miss.
The Courseiva GSEC question bank contains 8 questions in the Vulnerability Scanning and Penetration Testing domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Vulnerability Scanning and Penetration Testing domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included