Courseiva

GCIH · topic practice

Scanning and Mapping practice questions

This domain covers reconnaissance and network discovery using Nmap and related tooling: host discovery, port scanning techniques, timing templates, and firewall/IDS evasion. GCIH questions present incident-handler scenarios where you must choose the correct scan type, source port, or timing template for a target environment, balancing thoroughness against stealth, accuracy, and the risk of disrupting fragile or sensitive systems.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Scanning and Mapping

What the exam tests

What to know about Scanning and Mapping

Be able to select the right Nmap scan type, source port, and timing template for a given scenario, and explain what each reveals. The most important thing: match scan aggressiveness to the environment, using slow timing for fragile systems and source-port tricks only to bypass simple filters.

Nmap timing templates T0-T5 and their effect on scan speed, accuracy, and target stability

TCP scan types including SYN, connect, FIN, XMAS, NULL, and ACK for filter mapping

Source port manipulation such as --source-port 53 to appear as DNS traffic

Firewall and IDS evasion options including fragmentation, decoys, and idle scans

Watch out for

Common Scanning and Mapping exam traps

  • ▸Assuming aggressive timing templates like T4/T5 always work; on high-latency links they cause missed ports and false negatives from timeouts.
  • ▸Confusing ACK scans, which map firewall rules rather than open ports, with SYN or connect scans that actually identify listening services.
  • ▸Choosing a fast timing template for fragile ICS/SCADA segments when T0 or T1 is needed to avoid overwhelming or crashing sensitive devices.

Practice set

Scanning and Mapping questions

20 questions · select your answer, then reveal the explanation

An incident responder needs to identify active hosts on a segmented network while minimizing the risk of triggering IDS alerts. Which Nmap technique is most appropriate for a stealthy discovery scan?

When conducting network mapping, which TWO actions are considered best practice for ensuring the scan remains within the defined scope of an incident response engagement?

When mapping a network that employs egress filtering, which TWO scanning methodologies will likely produce inaccurate or incomplete results?

An incident handler is performing an authorized network discovery on a segmented enterprise network and needs to identify active hosts without triggering aggressive firewall alarms. Which Nmap scanning technique best achieves stealthy host discovery while minimizing noise?

An incident handler is tasked with auditing a corporate network for unauthorized live hosts without triggering aggressive firewall alarms or intrusion detection systems. Which Nmap scanning technique is best suited for discovering active hosts while minimizing the generation of traditional connection-state logs on stateful packet inspection firewalls?

During an internal network vulnerability assessment, an incident handler needs to perform host discovery across a heavily segmented corporate environment where standard ICMP Echo requests are completely blocked by internal host firewalls. Which TWO Nmap discovery techniques should the analyst select to reliably identify live hosts without relying on ICMP Echo? (Choose TWO)

Question 7mediummultiple choice
Review the full subnetting walkthrough →

During an incident response engagement, you must determine which hosts on a /24 subnet are alive without sending any TCP or UDP packets that could be logged by host-based firewalls. Which Nmap scan technique should you use?

An incident responder is mapping a network protected by a stateful firewall that drops unsolicited TCP packets. The responder needs to identify open TCP ports on a target host. Which two Nmap scan types are most likely to succeed in this environment? (Choose two.)

You are conducting an authorized vulnerability assessment on a web server farm. The firewall between your scanner and the targets drops all TCP packets with the SYN flag set to ports other than 80 and 443, but it allows TCP packets with the ACK flag set to any port. You need to determine which ports are open on the target hosts. Which Nmap scan type is most likely to yield useful results in this environment?

An incident handler is mapping a large, routed enterprise network and needs to identify live hosts efficiently while minimizing the scan's impact on network performance. The network has multiple subnets and some hosts block ICMP echo requests. Which two Nmap techniques should be used together to achieve accurate host discovery with reduced scan time? (Choose two.)

Which Nmap flag is essential when you need to perform OS fingerprinting to determine the target operating system version during an incident response assessment?

A responder is performing a vulnerability scan on a segment containing industrial control systems. Which Nmap timing template should be used to avoid disrupting sensitive, potentially fragile hardware?

Which tool is best suited for identifying potentially misconfigured SMB services that could be leveraged for lateral movement within a compromised Windows environment?

Why is it important to randomize the target IP addresses when performing a large-scale network scan?

Which Nmap scan type should be used when the goal is to map the topology of a network and identify active hosts without establishing any TCP or UDP connections?

A responder needs to map an internal network but cannot use standard tools due to strict endpoint protection. Which technique can be used with native command-line tools to perform a basic port check on a remote host?

Question 17mediummultiple choice
Read the full DNS explanation →

Which Nmap scan flag allows a responder to bypass simple packet filters by using specific source ports, such as port 53, to appear as legitimate DNS traffic?

Which Nmap argument should be used to display the reason why a port is reported as 'open', 'closed', or 'filtered' in the scan results?

What is the primary risk associated with using 'aggressive' scan timing templates (like T4 or T5) in an environment with high network latency?

An incident handler is performing an authorized network discovery scan on a perimeter segment. To bypass simple static stateful inspection firewalls that drop unexpected TCP SYN packets, the analyst decides to utilize an ACK scan (-sA in Nmap). What is the primary limitation of utilizing this specific scan type during network mapping?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Scanning and Mapping sessions

Start a Scanning and Mapping only practice session

Every question in these sessions is drawn from the Scanning and Mapping domain — nothing else.

Related practice questions

Related GCIH topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GCIH exam test about Scanning and Mapping?
Be able to select the right Nmap scan type, source port, and timing template for a given scenario, and explain what each reveals. The most important thing: match scan aggressiveness to the environment, using slow timing for fragile systems and source-port tricks only to bypass simple filters.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Scanning and Mapping questions in a focused session?
Yes — the session launcher on this page draws every question from the Scanning and Mapping domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GCIH topics?
Use the topic links above to move to related areas, or go back to the GCIH question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GCIH exam covers. They are not copied from any real exam or dump site.