GPEN Vulnerability Scanning Practice Question
A penetration tester is preparing to run a credentialed vulnerability scan against a mixed environment of Windows Server 2019 and Ubuntu 20.04 hosts on an internal /24 subnet. The tester wants to reduce scan duration and network load while still detecting missing patches and misconfigurations. Which two scanning techniques should the tester implement to achieve these goals? (Choose two.)
⚠ Common exam trap
The trap here is assuming that increasing scan aggressiveness or port coverage will speed up results, when in fact credentialed local checks are what reduce duration and network load while improving patch detection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use SSH and SMB credentials to allow the scanner to query the local patch database and installed software inventory.
Credentialed scanning with local security checks is the most efficient way to detect missing patches and misconfigurations while minimizing network traffic and scan time. Supplying administrative credentials for Windows and SSH credentials for Linux allows the scanner to read local patch databases and software inventories directly, avoiding extensive remote probing. This approach improves accuracy and reduces load compared to unauthenticated or overly aggressive scanning methods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use SSH and SMB credentials to allow the scanner to query the local patch database and installed software inventory.
Why this is correct
Providing SSH and SMB credentials enables authenticated checks that query local patch databases and software inventories directly. This yields accurate detection of missing patches and misconfigurations while minimizing network probes, thereby reducing scan duration and load. It is a core technique for credentialed scanning in mixed Windows and Linux environments.
- ✗
Configure the scanner to perform a SYN stealth scan on all 65,535 TCP ports for every host before authenticating.
Why it's wrong here
A full-port SYN scan is unauthenticated and generates large amounts of traffic, increasing scan duration. It does not leverage credentials to inspect patch state or configuration, so it fails to meet the goal of reducing load while detecting missing patches. It may also trigger IDS/IPS alerts unnecessarily.
- ✗
Limit the scan to a predefined list of common ports and disable all plugin families except 'Denial of Service'.
Why it's wrong here
Restricting ports reduces coverage and disabling all but the DoS family removes patch and configuration checks entirely. This would miss missing patches and misconfigurations, directly contradicting the objective. It also unnecessarily runs intrusive DoS tests that can harm systems without providing useful vulnerability data.
- ✓
Enable local security checks on the scan policy and provide administrative credentials for each target.
Why this is correct
Local security checks run directly on the target via authenticated sessions, allowing the scanner to read patch levels, registry settings, and installed packages without sending many probing packets. This drastically reduces scan time and network traffic while improving patch and misconfiguration detection accuracy compared to unauthenticated remote checks.
- ✗
Set the scanner to use a very aggressive timing template to maximize parallelism across all hosts.
Why it's wrong here
Aggressive timing increases packet volume and concurrency, which can overwhelm network devices, cause packet loss, and actually lengthen scan times due to retransmissions. It does not improve patch or configuration detection and risks disrupting production services, making it a poor choice for reducing load and duration.
Visual reference
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.