Courseiva
Scanning and Mapping →mediumMultiple Choice

GCIH Scanning and Mapping Practice Question

Why is it important to randomize the target IP addresses when performing a large-scale network scan?

⚠ Common exam trap

Candidates often confuse target IP randomization with changing the source IP address (spoofing) or think it is designed to bypass authentication mechanisms rather than avoiding IDS/IPS volume-based traffic thresholds.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To avoid triggering threshold-based IDS alerts on specific subnets.

Randomizing scan targets is a defensive measure against triggering automated threshold-based IDS/IPS alerts. By jumping between different subnets, the scanner avoids concentrating traffic on a single point in the network, which effectively prevents the security system from correlating multiple hits on a single host or subnet, thereby keeping the responder's reconnaissance activity below the typical detection thresholds of the organization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To reduce the scan duration by optimizing packet routing.

    Why it's wrong here

    Randomization does not optimize packet routing; in fact, it can sometimes increase latency due to the overhead of switching targets constantly. The primary purpose of randomization is to evade detection, not to improve the performance or efficiency of the scanning engine. Speed is actually sacrificed for the sake of stealth.

  • ✗

    To bypass the target operating system's rate limiting.

    Why it's wrong here

    While some rate-limiting occurs on individual hosts, randomization is primarily used to avoid network-wide intrusion detection triggers. It does not effectively bypass OS-level rate limiting because, even with randomization, individual hosts will eventually receive probes at a rate determined by the overall scanning speed, which can still trigger local security policies.

  • ✓

    To avoid triggering threshold-based IDS alerts on specific subnets.

    Why this is correct

    Randomizing target IP addresses spreads the scanning traffic across the entire network, preventing any single subnet or host from seeing a large spike in connection attempts. This significantly lowers the likelihood of triggering signature-based or threshold-based alerts, allowing the responder to complete the discovery process without immediate detection by security systems.

  • ✗

    To ensure the scanner utilizes all available network interfaces.

    Why it's wrong here

    Randomizing IP addresses does not influence which network interface Nmap uses to send packets. The selection of network interface is typically determined by the routing table and command-line arguments. Randomization is strictly a technique for obfuscating the scanning pattern to evade detection, not an optimization for the underlying network hardware performance.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.