Courseiva
Scanning and Mapping →hardMultiple Choice

GCIH Scanning and Mapping Practice Question

A responder needs to map an internal network but cannot use standard tools due to strict endpoint protection. Which technique can be used with native command-line tools to perform a basic port check on a remote host?

⚠ Common exam trap

Candidates often suggest installing third-party tools like Netcat or Nmap on a restricted host. This violates security policies and triggers endpoint detection; using native built-in commands is the only compliant path.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using a PowerShell Test-NetConnection command.

Using native tools like PowerShell or Netcat allows for basic network verification when dedicated scanning tools are blocked by endpoint security suites. By leveraging built-in functionality such as Test-NetConnection in PowerShell, a responder can verify reachability and port status without introducing unauthorized binaries, thereby maintaining the integrity of the environment while still performing necessary incident response data gathering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Using a PowerShell Test-NetConnection command.

    Why this is correct

    Test-NetConnection is a native Windows cmdlet that functions similarly to a simplified port scanner. It is an ideal, low-profile method for checking connectivity and port status on Windows systems. Because it is a built-in utility, it is less likely to be flagged by behavioral detection systems than external scanning tools.

  • ✗

    Running an nmap.exe binary from a USB drive.

    Why it's wrong here

    Executing unauthorized binaries like nmap.exe is almost certain to trigger endpoint detection and response (EDR) solutions. In restricted environments, using external tools is a high-risk activity that may alert the adversary or security team to the presence of the responder, potentially compromising the ongoing incident investigation and the team's professional standing.

  • ✗

    Initiating a telnet session to every port.

    Why it's wrong here

    Telnet is an outdated and insecure protocol, and modern systems often have the client disabled by default. Attempting to initiate manual telnet sessions to every port is inefficient and prone to errors. Furthermore, this activity is highly visible to network monitoring tools and does not provide an automated mapping capability.

  • ✗

    Pinging the broadcast address of the subnet.

    Why it's wrong here

    Pinging a broadcast address is a classic technique that is frequently blocked by modern network configurations to prevent broadcast storms and reconnaissance. Relying on this for port verification is ineffective as it provides no information about specific port statuses, only general network activity, and is often ignored by modern host operating systems.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.