Courseiva
Scanning and Mapping →mediumMultiple Choice

GCIH Scanning and Mapping Practice Question

Which Nmap scan flag allows a responder to bypass simple packet filters by using specific source ports, such as port 53, to appear as legitimate DNS traffic?

⚠ Common exam trap

Candidates frequently confuse source port manipulation with destination port manipulation. They mistakenly believe changing the destination port is the primary method to bypass filters, ignoring the specific syntax for source port spoofing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

--source-port 53

The --source-port flag allows for the manipulation of the packet's source port, which is a common technique for bypassing firewall rules configured to permit traffic from trusted services like DNS. This is useful for responders trying to map networks where basic ingress/egress filtering is in place, as it mimics expected protocol behavior to slip through simple security controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    --spoof-mac

    Why it's wrong here

    The --spoof-mac option is used to change the MAC address of the source interface, which is helpful for evading local network access controls but does nothing to bypass network-level firewall filtering based on ports. It is ineffective against rules that allow traffic based on port number or protocol source.

  • ✓

    --source-port 53

    Why this is correct

    Using --source-port 53 forces Nmap to use port 53 as the source port for all scanning packets. Since many firewalls are configured to allow DNS traffic (UDP/TCP 53) to pass through to internal hosts, this simple manipulation can bypass basic port-based filters, allowing the scanner to reach previously blocked internal network segments.

  • ✗

    -f

    Why it's wrong here

    The -f flag enables packet fragmentation, which breaks probes into smaller pieces. While it was historically used to bypass primitive filters, modern firewalls easily reassemble these fragments, rendering the technique ineffective. It is not designed to manipulate source port headers and does not help with port-based filter bypass in modern enterprise networks.

  • ✗

    --data-length

    Why it's wrong here

    The --data-length option appends random data to the sent packets. This is primarily used for evading signature-based detection by altering the packet's footprint, but it does not change the source port or help in bypassing port-based firewall rules. It is irrelevant to the requirement of appearing as legitimate DNS traffic.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.