GCIH Scanning and Mapping Practice Question
An incident handler is using Nmap to scan a target behind a firewall that blocks ICMP echo requests. The handler wants to increase the chances of host discovery. Which Nmap option should be used to send TCP SYN packets to a specific port for host discovery?
⚠ Common exam trap
The trap here is focusing on ICMP-based options when the firewall blocks ICMP; TCP-based discovery is needed instead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
-PS
When ICMP is blocked, using TCP-based host discovery can improve results. The -PS option sends TCP SYN packets to specified ports, and a response (SYN/ACK or RST) indicates the host is up. This method is more likely to succeed through firewalls that allow TCP traffic, making it the correct answer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
-PP
Why it's wrong here
The -PP option sends ICMP timestamp requests, which are also ICMP-based and likely blocked by the same firewall. It is not a TCP-based method and thus does not meet the requirement of using TCP SYN packets for host discovery.
- ✓
-PS
Why this is correct
The -PS option performs a TCP SYN ping, sending SYN packets to specified ports (default 80) to discover hosts. If the target responds with SYN/ACK or RST, it is considered up. This is effective when ICMP is blocked, as it uses TCP packets that may be allowed through the firewall, making it the correct choice.
- ✗
-PE
Why it's wrong here
The -PE option sends ICMP echo requests, which are explicitly blocked by the firewall in this scenario. Using this option would not help discover hosts because the ICMP packets will be dropped, leading to false negatives.
- ✗
-PA
Why it's wrong here
The -PA option performs a TCP ACK ping, sending ACK packets to specified ports. While it can discover hosts, it relies on ACK packets that may be dropped by stateful firewalls or not elicit a response from all hosts. It is less reliable than SYN ping for host discovery when ICMP is blocked.
Visual reference
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.