Courseiva

GCIH · domain

Scanning and Mapping

This domain covers reconnaissance and network discovery using Nmap and related tooling: host discovery, port scanning techniques, timing templates, and firewall/IDS evasion. GCIH questions present incident-handler scenarios where you must choose the correct scan type, source port, or timing template for a target environment, balancing thoroughness against stealth, accuracy, and the risk of disrupting fragile or sensitive systems.

21 questions3 easy14 medium4 hard

Focused practice

Practice Scanning and Mapping questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Scanning and Mapping

Be able to select the right Nmap scan type, source port, and timing template for a given scenario, and explain what each reveals. The most important thing: match scan aggressiveness to the environment, using slow timing for fragile systems and source-port tricks only to bypass simple filters.

Nmap timing templates T0-T5 and their effect on scan speed, accuracy, and target stability

TCP scan types including SYN, connect, FIN, XMAS, NULL, and ACK for filter mapping

Source port manipulation such as --source-port 53 to appear as DNS traffic

Firewall and IDS evasion options including fragmentation, decoys, and idle scans

Watch out for

Common Scanning and Mapping exam traps

  • ▸Assuming aggressive timing templates like T4/T5 always work; on high-latency links they cause missed ports and false negatives from timeouts.
  • ▸Confusing ACK scans, which map firewall rules rather than open ports, with SYN or connect scans that actually identify listening services.
  • ▸Choosing a fast timing template for fragile ICS/SCADA segments when T0 or T1 is needed to avoid overwhelming or crashing sensitive devices.

Question index

All Scanning and Mapping questions (21)

Click any question to see the full explanation, or start a practice session above.

1

An incident handler is mapping a flat internal subnet and wants Nmap to identify live hosts without performing port scans on every address. The handler also needs the scan to work when ICMP echo requests are blocked by host-based firewalls. Which Nmap option should be used?

Medium
2

An incident handler needs to quickly identify all live hosts on a large corporate network without performing port scans. Which Nmap command should be used?

Easy
3

Which Nmap scan type should be used when the goal is to map the topology of a network and identify active hosts without establishing any TCP or UDP connections?

Medium
4

An incident handler is mapping a DMZ segment and needs to determine whether a suspicious host at 172.16.5.22 is reachable before launching a targeted service scan. The host may be protected by a host-based firewall that drops TCP SYN packets, but it is known to run a service on UDP port 123. Which Nmap command should the handler use to most reliably determine if the host is alive?

Medium
5

You are analyzing a packet capture from a compromised host and notice a series of TCP packets with the SYN flag set, sent to sequential ports on multiple internal hosts. The source IP is the compromised host, and the destination ports range from 1 to 1024. The packets are spaced approximately 0.5 seconds apart. Which Nmap scan type is most consistent with this traffic pattern?

Hard
6

An incident handler is using Nmap to scan a target behind a firewall that blocks ICMP echo requests. The handler wants to increase the chances of host discovery. Which Nmap option should be used to send TCP SYN packets to a specific port for host discovery?

Hard
7

An incident handler executes the Nmap command shown in the exhibit against a known target server. Based on the output provided, which underlying mechanism enables Nmap to determine that port 80 is open without completing a full three-way TCP handshake?

Medium
8

Why is it important to randomize the target IP addresses when performing a large-scale network scan?

Medium
9

Which Nmap argument should be used to display the reason why a port is reported as 'open', 'closed', or 'filtered' in the scan results?

Medium
10

A responder is scanning a target host and wants to determine which IP protocols (e.g., ICMP, IGMP, TCP) are supported by the target. Which Nmap scan type should be used?

Medium
11

An incident responder is validating the perimeter firewall ruleset by scanning from an external vantage point. The team wants to confirm which TCP ports are reachable through the firewall and also determine whether UDP services are exposed. Which TWO Nmap scan techniques should the responder combine to accomplish this? (Choose two.)

Hard
12

Which tool is best suited for identifying potentially misconfigured SMB services that could be leveraged for lateral movement within a compromised Windows environment?

Medium
13

A responder needs to map an internal network but cannot use standard tools due to strict endpoint protection. Which technique can be used with native command-line tools to perform a basic port check on a remote host?

Hard
14

During an incident response investigation, you need to identify all hosts on a subnet that are responding to ARP requests. You have administrative access to a Linux workstation on the same subnet and want to use Nmap to perform this discovery without sending any IP packets. Which Nmap option should you use?

Medium
15

An incident handler is performing an authorized network discovery scan on a perimeter segment. To bypass simple static stateful inspection firewalls that drop unexpected TCP SYN packets, the analyst decides to utilize an ACK scan (-sA in Nmap). What is the primary limitation of utilizing this specific scan type during network mapping?

Medium
16

Which Nmap flag is essential when you need to perform OS fingerprinting to determine the target operating system version during an incident response assessment?

Medium
17

Which Nmap scan flag allows a responder to bypass simple packet filters by using specific source ports, such as port 53, to appear as legitimate DNS traffic?

Medium
18

During an authorized discovery scan of a DMZ, an incident responder needs Nmap to report the reason each port is classified as open, closed, or filtered so the team can distinguish a firewall drop from a host reset. Which Nmap option should the responder add to the command line?

Easy
19

What is the primary risk associated with using 'aggressive' scan timing templates (like T4 or T5) in an environment with high network latency?

Medium
20

During an authorized incident response engagement, you need to determine whether a specific suspicious host at 10.20.30.40 is alive before launching a full port scan. You want a lightweight check that does not complete a TCP three-way handshake and works even when ICMP is blocked. Which Nmap command best accomplishes this initial liveness check?

Easy
21

A responder is performing a vulnerability scan on a segment containing industrial control systems. Which Nmap timing template should be used to avoid disrupting sensitive, potentially fragile hardware?

Medium

Frequently asked questions

What does the Scanning and Mapping domain cover on the GCIH exam?
Be able to select the right Nmap scan type, source port, and timing template for a given scenario, and explain what each reveals. The most important thing: match scan aggressiveness to the environment, using slow timing for fragile systems and source-port tricks only to bypass simple filters.
How many questions are in this domain?
This page lists all 21 Scanning and Mapping questions in the GCIH question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Scanning and Mapping questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gcih GIAC-GCIH scanning and mapping Practice Questions