Courseiva
Scanning and Mapping →mediumMultiple Choice

GCIH Scanning and Mapping Practice Question

An incident handler is mapping a DMZ segment and needs to determine whether a suspicious host at 172.16.5.22 is reachable before launching a targeted service scan. The host may be protected by a host-based firewall that drops TCP SYN packets, but it is known to run a service on UDP port 123. Which Nmap command should the handler use to most reliably determine if the host is alive?

⚠ Common exam trap

The trap here is assuming that a standard ping sweep or TCP SYN probe will always work, ignoring that host-based firewalls often block those specific probes while leaving UDP services reachable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

nmap -PU123 172.16.5.22

The handler needs a host discovery method that works despite TCP SYN being dropped. UDP port 123 is known to be running, so a UDP ping to that port (-PU123) is the most likely to elicit a response that confirms the host is alive. ICMP echo and TCP SYN probes may be blocked by the host-based firewall, and the default host discovery mix in -sn may also fail. Therefore, the UDP ping is the most reliable choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    nmap -PU123 172.16.5.22

    Why this is correct

    The -PU option performs a UDP ping by sending a UDP packet to the specified port. If the host is alive and the port is closed, it will respond with an ICMP port unreachable message; if the port is open, it may respond with a UDP packet or no response, but the lack of an ICMP unreachable can still indicate the host is up. Because the scenario specifies that UDP port 123 is running, this probe is likely to elicit a response, making it the most reliable method to determine if the host is alive despite TCP SYN being dropped.

  • ✗

    nmap -PE 172.16.5.22

    Why it's wrong here

    The -PE option sends an ICMP echo request (ping). Many host-based firewalls and network devices are configured to block ICMP echo requests by default. If the host blocks ICMP, this probe will fail and Nmap will consider the host down. Since the scenario describes a host that drops TCP SYN packets, it may also block ICMP, so this method is unreliable for determining liveness.

  • ✗

    nmap -PS22 172.16.5.22

    Why it's wrong here

    The -PS option sends TCP SYN packets to the specified port (22 in this case). The scenario explicitly states that the host-based firewall drops TCP SYN packets, so this probe will not receive a SYN/ACK or RST response. Nmap will likely mark the host as down unless other probes succeed. Therefore, this command is not the most reliable way to confirm the host is alive in this environment.

  • ✗

    nmap -sn 172.16.5.22

    Why it's wrong here

    The -sn option performs host discovery using a combination of ICMP echo, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests. If the host-based firewall drops those specific probes, Nmap will mark the host as down and skip it, even though UDP port 123 might be open. Because the scenario states that TCP SYN packets are dropped, this command is not the most reliable way to confirm the host is alive.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.