GCIH Scanning and Mapping Practice Question
An incident responder is validating the perimeter firewall ruleset by scanning from an external vantage point. The team wants to confirm which TCP ports are reachable through the firewall and also determine whether UDP services are exposed. Which TWO Nmap scan techniques should the responder combine to accomplish this? (Choose two.)
⚠ Common exam trap
The trap here is choosing multiple TCP scan types, such as SYN and connect or FIN, when the requirement explicitly includes UDP exposure that only a UDP scan can address.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
UDP scan (-sU)
Validating a perimeter ruleset for both protocols requires a TCP scan and a UDP scan. The TCP SYN scan is the standard, efficient way to determine which TCP ports the firewall permits, while the UDP scan is the only Nmap technique that probes UDP ports and interprets ICMP unreachable responses or service replies to classify them. Together they cover the TCP and UDP rule sets the team wants to verify.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
UDP scan (-sU)
Why this is correct
A UDP scan sends UDP payloads and interprets ICMP port-unreachable messages or application responses to classify UDP ports. Because the team also wants to know whether UDP services are exposed, -sU is required; without it, no UDP probing occurs and the firewall's UDP rules cannot be validated from the external vantage point.
- ✓
TCP SYN scan (-sS)
Why this is correct
A TCP SYN scan sends a SYN and interprets the response, making it fast and reliable for determining which TCP ports the perimeter firewall allows through. It clearly distinguishes open (SYN-ACK), closed (RST), and filtered (no response or ICMP unreachable) states, which is exactly what the responder needs for TCP rule validation.
- ✗
FIN scan (-sF)
Why it's wrong here
A FIN scan sends a TCP packet with only the FIN flag set and relies on RFC 793 behavior where closed ports respond with RST and open ports ignore the packet. Many modern firewalls and operating systems do not follow this behavior, producing unreliable results, and it provides no UDP visibility, making it a poor choice for perimeter rule validation.
- ✗
TCP connect scan (-sT)
Why it's wrong here
A TCP connect scan completes the full three-way handshake using the operating system's connect call. It produces the same open/closed information as a SYN scan for TCP but adds no UDP coverage, and it is noisier and slower, so it does not add value beyond the SYN scan for this firewall validation task.
- ✗
Idle scan (-sI)
Why it's wrong here
An idle scan uses a third-party zombie host to bounce probes and hide the scanner's source address. It can enumerate TCP ports on some targets but requires a suitable zombie with predictable IP ID values, is unreliable across modern networks, and offers no UDP scanning capability, so it does not meet the team's dual protocol requirement.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.