Courseiva
Vulnerability Scanning →easyMultiple Choice

GPEN Vulnerability Scanning Practice Question

A penetration tester is configuring a vulnerability scanner to assess a sensitive production network. The tester wants to avoid causing service disruptions or overwhelming network devices. Which scanner setting should be adjusted to best achieve this?

⚠ Common exam trap

The trap here is equating speed or stealth with safety, when in production environments the priority is limiting concurrency and avoiding intrusive checks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable safe checks and reduce the scan's performance settings to limit simultaneous connections.

To avoid disrupting a sensitive production network, the scanner should be configured with safe checks enabled and performance settings lowered to reduce concurrent connections and packet rate. This minimizes the risk of overwhelming devices or causing service outages. Disabling DoS plugins and avoiding aggressive timing are also important, but safe checks and reduced performance are the primary controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable all plugin families except those that perform denial-of-service testing to quickly identify weak points.

    Why it's wrong here

    Denial-of-service plugins are specifically designed to stress or crash services, which is the opposite of avoiding disruptions. Running only these plugins would likely cause outages and provide an incomplete vulnerability picture. They should be avoided entirely on production networks unless explicitly authorized in a controlled test window.

  • ✗

    Set the scanner to use a random port order and maximum timing template to evade detection.

    Why it's wrong here

    Maximum timing template increases scan speed and packet volume, which can overwhelm network devices and trigger timeouts. Random port order may help evade simple IDS but does not reduce load. This setting prioritizes stealth over safety and is inappropriate for a sensitive production network where avoiding disruption is the primary concern.

  • ✗

    Increase the maximum number of concurrent hosts and checks per host to finish faster.

    Why it's wrong here

    Increasing concurrency raises network and target load, which can cause packet loss, service timeouts, or even crashes on fragile systems. This directly opposes the goal of avoiding disruptions. Higher concurrency is suitable for non-production or robust environments, but not for sensitive production networks where stability is paramount.

  • ✓

    Enable safe checks and reduce the scan's performance settings to limit simultaneous connections.

    Why this is correct

    Safe checks avoid plugins known to disrupt services, and lowering performance settings reduces concurrent connections and packet rate. This combination minimizes the risk of overwhelming network devices or causing service outages. It is the standard approach for scanning sensitive production environments where availability is critical.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.