Courseiva
Scanning and Mapping →easyMultiple Choice

GCIH Scanning and Mapping Practice Question

During an authorized incident response engagement, you need to determine whether a specific suspicious host at 10.20.30.40 is alive before launching a full port scan. You want a lightweight check that does not complete a TCP three-way handshake and works even when ICMP is blocked. Which Nmap command best accomplishes this initial liveness check?

⚠ Common exam trap

The trap here is assuming that host discovery requires a full port scan, when Nmap's -sn flag performs liveness checks using multiple protocols without scanning any ports.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

nmap -sn 10.20.30.40

The -sn ping scan performs host discovery without port scanning and uses multiple probe types, including TCP SYN to port 443 and TCP ACK to port 80, so it can identify live hosts even when ICMP is blocked. This makes it the correct lightweight liveness check before committing to a full port scan. The other options either skip discovery, perform a port scan, or perform OS fingerprinting, all of which are heavier or not designed for simple liveness detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    nmap -sn 10.20.30.40

    Why this is correct

    The -sn flag performs a ping scan (host discovery) only, without port scanning. Nmap sends ICMP echo, TCP SYN to port 443, TCP ACK to port 80, and an ARP request on local networks. Because it uses multiple probe types, it can detect liveness even when ICMP is filtered, making it ideal for a quick, low-noise check.

  • ✗

    nmap -sS 10.20.30.40

    Why it's wrong here

    A TCP SYN scan (-sS) is a port scan, not a host discovery method. It sends SYN packets to a range of ports and interprets SYN/ACK, RST, or silence to classify port states. While it is stealthy, it is heavier than a simple ping scan and is not the intended tool for a preliminary liveness check.

  • ✗

    nmap -Pn 10.20.30.40

    Why it's wrong here

    The -Pn flag skips host discovery entirely and treats the target as online, then proceeds to scan its ports. It does not perform a liveness check at all, so it cannot tell you whether the host is actually alive. Using it here would defeat the purpose of a lightweight discovery step before a full scan.

  • ✗

    nmap -O 10.20.30.40

    Why it's wrong here

    The -O flag enables operating system fingerprinting, which requires a port scan and sends many crafted probes. It is far more intrusive and noisy than a simple liveness check and can trigger endpoint protections. It is not appropriate for a lightweight host discovery step before a full scan.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.