Courseiva
Vulnerability Scanning →mediumMultiple Choice

GPEN Vulnerability Scanning Practice Question

A penetration tester is preparing to scan a network that includes a mix of traditional IT systems and industrial control systems (ICS). The tester wants to minimize the risk of disrupting ICS devices. Which scanning approach is MOST appropriate for the ICS segment?

⚠ Common exam trap

The trap here is assuming that Safe Checks or a maintenance window makes active scanning safe for ICS, when only passive monitoring guarantees no disruption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a passive scanner that only listens to network traffic without sending packets.

Passive scanning is the safest method for ICS because it does not send any traffic that could disrupt fragile devices. It relies on observing existing network traffic to identify assets and potential vulnerabilities. Active scanning, even with Safe Checks or during maintenance, carries inherent risk of causing outages. For OT environments, passive monitoring is the recommended first step before any active testing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Perform an aggressive Nmap scan with OS detection and version scanning.

    Why it's wrong here

    Aggressive Nmap scans send numerous probes, including malformed packets and intense version detection, which can crash fragile ICS devices. ICS often runs on real-time operating systems with limited resources and no tolerance for unexpected traffic. This approach risks causing outages and is strongly discouraged in OT environments. It is not appropriate for sensitive industrial networks.

  • ✓

    Use a passive scanner that only listens to network traffic without sending packets.

    Why this is correct

    Passive scanning monitors existing traffic to identify devices and vulnerabilities without injecting any packets. This eliminates the risk of disrupting ICS devices, which may be sensitive to unexpected probes. Tools like Tenable Nessus Passive Scanner or Wireshark with protocol dissectors can inventory assets and detect issues. It is the safest approach for fragile OT environments where uptime is critical.

  • ✗

    Scan the ICS segment during a planned maintenance window with Safe Checks enabled.

    Why it's wrong here

    Even with Safe Checks and a maintenance window, active scanning can still disrupt ICS devices because Safe Checks is not foolproof and some ICS protocols are sensitive to any unexpected traffic. While a maintenance window reduces business impact, it does not eliminate the technical risk of crashing devices. Passive scanning remains safer. Thus this is not the best choice.

  • ✗

    Run a credentialed scan with default settings to get the most accurate results.

    Why it's wrong here

    Credentialed scans still involve active probing and may run intrusive checks. ICS devices often lack standard credential mechanisms or cannot handle the load of a full vulnerability scan. Default settings may include unsafe plugins. Even with credentials, active scanning can disrupt operations. Therefore this is not the most appropriate approach for ICS segments without extensive precautions.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.