Courseiva
Scanning and Mapping →mediumMultiple Choice

GCIH Scanning and Mapping Practice Question

An incident handler is mapping a flat internal subnet and wants Nmap to identify live hosts without performing port scans on every address. The handler also needs the scan to work when ICMP echo requests are blocked by host-based firewalls. Which Nmap option should be used?

⚠ Common exam trap

The trap here is assuming that host discovery depends on ICMP echo, when Nmap's -sn default probes also include TCP SYN and ACK to common web ports.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

-sn

The -sn option performs host discovery only and skips port scanning, and Nmap's default discovery probes include TCP SYN to port 443 and TCP ACK to port 80 in addition to ICMP, so hosts that block ping but expose web services are still detected. This satisfies both the discovery-only and ICMP-blocked requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    -sn

    Why this is correct

    The -sn option performs host discovery only, skipping port scanning entirely. Nmap still sends ICMP echo, TCP SYN to port 443, TCP ACK to port 80, and an ICMP timestamp request by default, so it can detect hosts that block ICMP but respond on common TCP ports, which fits the flat subnet requirement.

  • ✗

    -Pn

    Why it's wrong here

    The -Pn option tells Nmap to skip host discovery and treat all targets as online, then proceed to port scanning. It is useful when ICMP and TCP probes are filtered, but it does not by itself perform discovery-only mapping; it increases scan traffic because every address is port-scanned regardless of liveness.

  • ✗

    -sU

    Why it's wrong here

    The -sU option enables UDP port scanning, which is slow and unrelated to the goal of host discovery without port scans. While UDP probes can sometimes reveal live hosts, using -sU to map a subnet is inefficient and noisy, and it does not provide the discovery-only behavior the handler needs.

  • ✗

    -sS

    Why it's wrong here

    The -sS option performs a TCP SYN port scan against the specified ports, not a host discovery sweep. It is efficient and stealthy for port enumeration, but it does not fulfill the requirement to identify live hosts without scanning ports, and it may miss hosts that have no open ports on the scanned list.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.