GPEN Vulnerability Scanning Practice Question
A penetration tester is using Nmap to scan a target network and wants to identify open UDP ports. The tester runs a UDP scan but notices that many ports are reported as 'open|filtered'. Which technique can help determine whether these ports are actually open or filtered?
⚠ Common exam trap
The trap here is thinking that increasing timeout or retries will resolve the 'open|filtered' state, when in fact it only addresses packet loss, not the ambiguity between open and filtered.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Send a UDP packet with a known payload and analyze the response.
Sending a UDP packet with a known payload that triggers a response from a specific service can help determine if a port is open. If the service responds, the port is open; if no response or an ICMP unreachable is received, it may be filtered. This active probing provides more definitive results than generic scans.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a TCP ACK scan to infer UDP port states.
Why it's wrong here
TCP ACK scan is used to map firewall rules for TCP, not UDP. It cannot provide information about UDP port states. UDP and TCP are separate protocols, and techniques for one do not apply to the other.
- ✗
Perform a TCP SYN scan on the same ports.
Why it's wrong here
TCP SYN scan targets TCP ports, not UDP. It cannot determine the state of UDP ports. While it might reveal related services, it does not resolve the ambiguity of 'open|filtered' UDP ports, which require UDP-specific techniques.
- ✗
Run a UDP scan with a longer timeout and more retries.
Why it's wrong here
Increasing timeout and retries may reduce the number of 'open|filtered' results due to packet loss, but it does not actively distinguish between open and filtered ports. It only improves reliability of the same ambiguous classification, so it doesn't resolve the fundamental ambiguity.
- ✓
Send a UDP packet with a known payload and analyze the response.
Why this is correct
Sending a UDP packet with a payload that elicits a response from a specific service can help differentiate open ports from filtered ones. If a service is listening, it may reply with an ICMP port unreachable or a protocol-specific response. This technique is more reliable than relying on generic UDP probes.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.