GPEN Vulnerability Scanning Practice Question
A penetration tester is planning a vulnerability scan of a network that includes legacy systems and IoT devices. The tester needs to minimize the risk of disrupting these fragile devices while still gathering useful vulnerability data. Which two actions should the tester take? (Choose two.)
⚠ Common exam trap
The trap here is thinking that increasing concurrency or using a SYN scan will speed things up without considering the impact on fragile devices; the key is to throttle and use safe checks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the scanner to throttle network traffic and reduce the number of concurrent hosts scanned.
Enabling safe checks and throttling network traffic are the two actions that directly reduce the risk of disrupting legacy systems and IoT devices. Safe checks avoid potentially harmful tests, while throttling and reduced concurrency prevent overwhelming devices with too much traffic. The other options either increase load, broaden the scan unnecessarily, or do not address the specific fragility of these devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure the scanner to throttle network traffic and reduce the number of concurrent hosts scanned.
Why this is correct
Throttling and reducing concurrency lower the load on the network and target devices. This helps prevent overwhelming legacy systems and IoT devices, which may have low bandwidth or processing power. By pacing the scan, the tester can avoid disruptions while still collecting vulnerability data over a longer period.
- ✗
Increase the scan's maximum number of concurrent checks per host to speed up the scan.
Why it's wrong here
Increasing concurrent checks can overwhelm fragile devices, causing them to crash or become unresponsive. This is especially risky for legacy systems and IoT devices with limited resources. The goal is to minimize disruption, so this action is counterproductive. It may also lead to false negatives if devices fail to respond.
- ✓
Enable 'Safe checks' in the scan policy to avoid tests that could cause denial-of-service.
Why this is correct
Safe checks are designed to avoid tests that could crash services or devices. For legacy systems and IoT devices that may not handle unexpected traffic well, this setting reduces the risk of disruption. It allows the scan to proceed without aggressive tests that might cause outages, while still identifying vulnerabilities that can be detected safely.
- ✗
Use a TCP SYN scan instead of a TCP connect scan to reduce the number of packets sent.
Why it's wrong here
A TCP SYN scan is stealthier and sends fewer packets than a full connect scan, but it can still disrupt fragile devices if they cannot handle half-open connections. The primary concern is not the number of packets but the nature of the tests. SYN scans are not inherently safe for legacy systems; they can cause resource exhaustion or crashes.
- ✗
Disable host discovery and scan all IP addresses in the range.
Why it's wrong here
Disabling host discovery (e.g., using -Pn in Nmap) forces scanning of all IPs, including those that are not active. This generates unnecessary traffic and can probe devices that might be offline or fragile, increasing the risk of disruption. It does not help minimize impact on legacy systems; instead, it broadens the scan unnecessarily.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.