Courseiva
Scanning and Mapping →mediumMultiple Choice

GCIH Scanning and Mapping Practice Question

Which Nmap flag is essential when you need to perform OS fingerprinting to determine the target operating system version during an incident response assessment?

⚠ Common exam trap

Candidates often confuse port scanning flags like -sS with operating system detection flags, incorrectly thinking standard SYN scans reveal OS versions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

-O

The -O flag instructs Nmap to perform TCP/IP stack fingerprinting, which analyzes specific behaviors of the target's networking stack. This is vital for responders to classify assets, identify potential legacy systems, and determine if the target matches known vulnerable OS versions during the scoping phase of an incident investigation or routine security audit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    -sV

    Why it's wrong here

    The -sV flag is used for version detection, which determines the software and version numbers running on open ports by interacting with the application layer. While useful for identifying service vulnerabilities, it does not provide information regarding the underlying operating system kernel or the network stack implementation of the target.

  • ✗

    -A

    Why it's wrong here

    The -A flag enables aggressive scan mode, which combines OS detection, version scanning, script scanning, and traceroute. While it does perform OS detection, it is considered too noisy for standard incident response tasks, as it triggers multiple signatures and may alert security teams to the presence of the responder.

  • ✓

    -O

    Why this is correct

    This flag specifically triggers the OS detection engine within Nmap. It probes the target with various TCP and ICMP packets and compares the responses to a database of known fingerprints. It is the focused command for identifying the target's operating system without the overhead of additional service or script scans.

  • ✗

    -sS

    Why it's wrong here

    The -sS flag performs a TCP SYN scan, which is used for port discovery rather than OS fingerprinting. While it is the default and most popular scan type for finding open ports, it lacks the specific analysis tools required to identify the operating system or kernel version of the target system.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.