GCIH · domain
Scanning and Mapping
This domain covers reconnaissance and network discovery using Nmap and related tooling: host discovery, port scanning techniques, timing templates, and firewall/IDS evasion. GCIH questions present incident-handler scenarios where you must choose the correct scan type, source port, or timing template for a target environment, balancing thoroughness against stealth, accuracy, and the risk of disrupting fragile or sensitive systems.
Focused practice
Practice Scanning and Mapping questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Scanning and Mapping
Be able to select the right Nmap scan type, source port, and timing template for a given scenario, and explain what each reveals. The most important thing: match scan aggressiveness to the environment, using slow timing for fragile systems and source-port tricks only to bypass simple filters.
Watch out for
Common Scanning and Mapping exam traps
- ▸Assuming aggressive timing templates like T4/T5 always work; on high-latency links they cause missed ports and false negatives from timeouts.
- ▸Confusing ACK scans, which map firewall rules rather than open ports, with SYN or connect scans that actually identify listening services.
- ▸Choosing a fast timing template for fragile ICS/SCADA segments when T0 or T1 is needed to avoid overwhelming or crashing sensitive devices.
Question index
All Scanning and Mapping questions (21)
Click any question to see the full explanation, or start a practice session above.
An incident handler is mapping a flat internal subnet and wants Nmap to identify live hosts without performing port scans on every address. The handler also needs the scan to work when ICMP echo requests are blocked by host-based firewalls. Which Nmap option should be used?
Medium2An incident handler needs to quickly identify all live hosts on a large corporate network without performing port scans. Which Nmap command should be used?
Easy3Which Nmap scan type should be used when the goal is to map the topology of a network and identify active hosts without establishing any TCP or UDP connections?
Medium4An incident handler is mapping a DMZ segment and needs to determine whether a suspicious host at 172.16.5.22 is reachable before launching a targeted service scan. The host may be protected by a host-based firewall that drops TCP SYN packets, but it is known to run a service on UDP port 123. Which Nmap command should the handler use to most reliably determine if the host is alive?
Medium5You are analyzing a packet capture from a compromised host and notice a series of TCP packets with the SYN flag set, sent to sequential ports on multiple internal hosts. The source IP is the compromised host, and the destination ports range from 1 to 1024. The packets are spaced approximately 0.5 seconds apart. Which Nmap scan type is most consistent with this traffic pattern?
Hard6An incident handler is using Nmap to scan a target behind a firewall that blocks ICMP echo requests. The handler wants to increase the chances of host discovery. Which Nmap option should be used to send TCP SYN packets to a specific port for host discovery?
Hard7An incident handler executes the Nmap command shown in the exhibit against a known target server. Based on the output provided, which underlying mechanism enables Nmap to determine that port 80 is open without completing a full three-way TCP handshake?
Medium8Why is it important to randomize the target IP addresses when performing a large-scale network scan?
Medium9Which Nmap argument should be used to display the reason why a port is reported as 'open', 'closed', or 'filtered' in the scan results?
Medium10A responder is scanning a target host and wants to determine which IP protocols (e.g., ICMP, IGMP, TCP) are supported by the target. Which Nmap scan type should be used?
Medium11An incident responder is validating the perimeter firewall ruleset by scanning from an external vantage point. The team wants to confirm which TCP ports are reachable through the firewall and also determine whether UDP services are exposed. Which TWO Nmap scan techniques should the responder combine to accomplish this? (Choose two.)
Hard12Which tool is best suited for identifying potentially misconfigured SMB services that could be leveraged for lateral movement within a compromised Windows environment?
Medium13A responder needs to map an internal network but cannot use standard tools due to strict endpoint protection. Which technique can be used with native command-line tools to perform a basic port check on a remote host?
Hard14During an incident response investigation, you need to identify all hosts on a subnet that are responding to ARP requests. You have administrative access to a Linux workstation on the same subnet and want to use Nmap to perform this discovery without sending any IP packets. Which Nmap option should you use?
Medium15An incident handler is performing an authorized network discovery scan on a perimeter segment. To bypass simple static stateful inspection firewalls that drop unexpected TCP SYN packets, the analyst decides to utilize an ACK scan (-sA in Nmap). What is the primary limitation of utilizing this specific scan type during network mapping?
Medium16Which Nmap flag is essential when you need to perform OS fingerprinting to determine the target operating system version during an incident response assessment?
Medium17Which Nmap scan flag allows a responder to bypass simple packet filters by using specific source ports, such as port 53, to appear as legitimate DNS traffic?
Medium18During an authorized discovery scan of a DMZ, an incident responder needs Nmap to report the reason each port is classified as open, closed, or filtered so the team can distinguish a firewall drop from a host reset. Which Nmap option should the responder add to the command line?
Easy19What is the primary risk associated with using 'aggressive' scan timing templates (like T4 or T5) in an environment with high network latency?
Medium20During an authorized incident response engagement, you need to determine whether a specific suspicious host at 10.20.30.40 is alive before launching a full port scan. You want a lightweight check that does not complete a TCP three-way handshake and works even when ICMP is blocked. Which Nmap command best accomplishes this initial liveness check?
Easy21A responder is performing a vulnerability scan on a segment containing industrial control systems. Which Nmap timing template should be used to avoid disrupting sensitive, potentially fragile hardware?
MediumOther domains
All GCIH exam domains
Frequently asked questions
- What does the Scanning and Mapping domain cover on the GCIH exam?
- Be able to select the right Nmap scan type, source port, and timing template for a given scenario, and explain what each reveals. The most important thing: match scan aggressiveness to the environment, using slow timing for fragile systems and source-port tricks only to bypass simple filters.
- How many questions are in this domain?
- This page lists all 21 Scanning and Mapping questions in the GCIH question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Scanning and Mapping questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.