GCIH Scanning and Mapping Practice Question
An incident handler needs to quickly identify all live hosts on a large corporate network without performing port scans. Which Nmap command should be used?
⚠ Common exam trap
It's easy for candidates to confuse host discovery with port scanning; -sn is specifically designed for host discovery only.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
nmap -sn 10.0.0.0/16
To quickly identify live hosts without port scanning, the -sn option is used. It performs host discovery using a combination of ICMP, TCP, and UDP probes, but does not scan ports. This is the standard Nmap command for ping sweeps, making it the correct answer for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
nmap -sU 10.0.0.0/16
Why it's wrong here
The -sU option initiates a UDP scan, which probes UDP ports on each host. This is a port scan, not a host discovery method, and it can be slow and unreliable. It does not meet the requirement of quickly identifying live hosts without port scanning.
- ✗
nmap -sV 10.0.0.0/16
Why it's wrong here
The -sV option enables version detection, which probes open ports to determine service and version information. This is a deep inspection technique that requires port scanning and is not suitable for simple host discovery. It would take much longer and generate more traffic than needed for identifying live hosts.
- ✓
nmap -sn 10.0.0.0/16
Why this is correct
The -sn option (ping scan) disables port scanning and only performs host discovery. It sends ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests to determine which hosts are up. This is the fastest way to identify live hosts without scanning ports, making it the correct choice for the scenario.
- ✗
nmap -sS 10.0.0.0/16
Why it's wrong here
The -sS option performs a TCP SYN scan, which attempts to identify open ports on each host. This goes beyond simple host discovery and will generate significant traffic, potentially triggering IDS alerts. It is not the appropriate command for quickly identifying live hosts without port scanning.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.