GCIH Scanning and Mapping Practice Question
An incident handler is mapping a flat internal subnet and wants Nmap to identify live hosts without performing port scans on every address. The handler also needs the scan to work when ICMP echo requests are blocked by host-based firewalls. Which Nmap option should be used?
⚠ Common exam trap
The trap here is assuming that host discovery depends on ICMP echo, when Nmap's -sn default probes also include TCP SYN and ACK to common web ports.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
-sn
The -sn option performs host discovery only and skips port scanning, and Nmap's default discovery probes include TCP SYN to port 443 and TCP ACK to port 80 in addition to ICMP, so hosts that block ping but expose web services are still detected. This satisfies both the discovery-only and ICMP-blocked requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
-sn
Why this is correct
The -sn option performs host discovery only, skipping port scanning entirely. Nmap still sends ICMP echo, TCP SYN to port 443, TCP ACK to port 80, and an ICMP timestamp request by default, so it can detect hosts that block ICMP but respond on common TCP ports, which fits the flat subnet requirement.
- ✗
-Pn
Why it's wrong here
The -Pn option tells Nmap to skip host discovery and treat all targets as online, then proceed to port scanning. It is useful when ICMP and TCP probes are filtered, but it does not by itself perform discovery-only mapping; it increases scan traffic because every address is port-scanned regardless of liveness.
- ✗
-sU
Why it's wrong here
The -sU option enables UDP port scanning, which is slow and unrelated to the goal of host discovery without port scans. While UDP probes can sometimes reveal live hosts, using -sU to map a subnet is inefficient and noisy, and it does not provide the discovery-only behavior the handler needs.
- ✗
-sS
Why it's wrong here
The -sS option performs a TCP SYN port scan against the specified ports, not a host discovery sweep. It is efficient and stealthy for port enumeration, but it does not fulfill the requirement to identify live hosts without scanning ports, and it may miss hosts that have no open ports on the scanned list.
Visual reference
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.