GCIH Scanning and Mapping Practice Question
Which Nmap scan flag allows a responder to bypass simple packet filters by using specific source ports, such as port 53, to appear as legitimate DNS traffic?
⚠ Common exam trap
Candidates frequently confuse source port manipulation with destination port manipulation. They mistakenly believe changing the destination port is the primary method to bypass filters, ignoring the specific syntax for source port spoofing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
--source-port 53
The --source-port flag allows for the manipulation of the packet's source port, which is a common technique for bypassing firewall rules configured to permit traffic from trusted services like DNS. This is useful for responders trying to map networks where basic ingress/egress filtering is in place, as it mimics expected protocol behavior to slip through simple security controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
--spoof-mac
Why it's wrong here
The --spoof-mac option is used to change the MAC address of the source interface, which is helpful for evading local network access controls but does nothing to bypass network-level firewall filtering based on ports. It is ineffective against rules that allow traffic based on port number or protocol source.
- ✓
--source-port 53
Why this is correct
Using --source-port 53 forces Nmap to use port 53 as the source port for all scanning packets. Since many firewalls are configured to allow DNS traffic (UDP/TCP 53) to pass through to internal hosts, this simple manipulation can bypass basic port-based filters, allowing the scanner to reach previously blocked internal network segments.
- ✗
-f
Why it's wrong here
The -f flag enables packet fragmentation, which breaks probes into smaller pieces. While it was historically used to bypass primitive filters, modern firewalls easily reassemble these fragments, rendering the technique ineffective. It is not designed to manipulate source port headers and does not help with port-based filter bypass in modern enterprise networks.
- ✗
--data-length
Why it's wrong here
The --data-length option appends random data to the sent packets. This is primarily used for evading signature-based detection by altering the packet's footprint, but it does not change the source port or help in bypassing port-based firewall rules. It is irrelevant to the requirement of appearing as legitimate DNS traffic.
Visual reference
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.