Courseiva
Scanning and Mapping →hardMultiple Choice

GCIH Scanning and Mapping Practice Question

An incident handler is using Nmap to scan a target behind a firewall that blocks ICMP echo requests. The handler wants to increase the chances of host discovery. Which Nmap option should be used to send TCP SYN packets to a specific port for host discovery?

⚠ Common exam trap

The trap here is focusing on ICMP-based options when the firewall blocks ICMP; TCP-based discovery is needed instead.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

-PS

When ICMP is blocked, using TCP-based host discovery can improve results. The -PS option sends TCP SYN packets to specified ports, and a response (SYN/ACK or RST) indicates the host is up. This method is more likely to succeed through firewalls that allow TCP traffic, making it the correct answer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    -PP

    Why it's wrong here

    The -PP option sends ICMP timestamp requests, which are also ICMP-based and likely blocked by the same firewall. It is not a TCP-based method and thus does not meet the requirement of using TCP SYN packets for host discovery.

  • ✓

    -PS

    Why this is correct

    The -PS option performs a TCP SYN ping, sending SYN packets to specified ports (default 80) to discover hosts. If the target responds with SYN/ACK or RST, it is considered up. This is effective when ICMP is blocked, as it uses TCP packets that may be allowed through the firewall, making it the correct choice.

  • ✗

    -PE

    Why it's wrong here

    The -PE option sends ICMP echo requests, which are explicitly blocked by the firewall in this scenario. Using this option would not help discover hosts because the ICMP packets will be dropped, leading to false negatives.

  • ✗

    -PA

    Why it's wrong here

    The -PA option performs a TCP ACK ping, sending ACK packets to specified ports. While it can discover hosts, it relies on ACK packets that may be dropped by stateful firewalls or not elicit a response from all hosts. It is less reliable than SYN ping for host discovery when ICMP is blocked.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.