Courseiva
Scanning and Mapping →easyMultiple Choice

GCIH Scanning and Mapping Practice Question

During an authorized discovery scan of a DMZ, an incident responder needs Nmap to report the reason each port is classified as open, closed, or filtered so the team can distinguish a firewall drop from a host reset. Which Nmap option should the responder add to the command line?

⚠ Common exam trap

Many candidates confuse verbosity options like -v or --packet-trace with the specific --reason flag that annotates each port state with its cause.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

--reason

Adding --reason to an Nmap scan causes each port entry to include the reason Nmap assigned the state, such as syn-ack for open, reset for closed, or no-response for filtered. This distinction is critical in a DMZ where a drop and a reset imply very different firewall or host behaviors, and it gives the responder defensible evidence for the report.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    -d

    Why it's wrong here

    The -d flag raises Nmap's debugging level and is intended for troubleshooting Nmap internals, not for summarizing port state rationale. Debug output is verbose and technical, often including timing and engine details, but it does not produce the concise per-port reason column that the responder needs for the DMZ report.

  • ✗

    -v

    Why it's wrong here

    The -v flag increases verbosity and shows more detail about the scan progress and open ports, but it does not print the underlying reason code for each port state. An analyst reading -v output still cannot tell whether a filtered result came from an ICMP unreachable, a silent drop, or a maximum-retransmission timeout.

  • ✗

    --packet-trace

    Why it's wrong here

    --packet-trace prints every packet sent and received during the scan, which is far more granular than reason codes and can generate enormous output on a large DMZ. It can help diagnose behavior, but it does not summarize per-port state reasoning in the results table, making it inefficient for this specific requirement.

  • ✓

    --reason

    Why this is correct

    The --reason option makes Nmap display the reason code for each port state, such as syn-ack, resets, or no-response, directly in the output. This lets the responder differentiate a closed port that returned a TCP RST from a filtered port that produced no reply, which is exactly what the DMZ analysis requires.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.