Courseiva

GPEN · domain

Scanning and Host Discovery

This domain covers Nmap-driven host discovery and port scanning: interpreting port states like open|filtered, selecting scan types (SYN, UDP, version detection), and sweeping subnets when ICMP is blocked. GPEN questions present scenarios with exhibits or command output and require you to choose correct Nmap syntax and explain scan behavior and limitations.

17 questions4 easy6 medium7 hard

Focused practice

Practice Scanning and Host Discovery questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Scanning and Host Discovery

You must read Nmap output, pick the right scan flags, and explain port states. The key skill is matching the command to the objective: -sV for versions, -sU for UDP, -Pn to skip host discovery, and knowing open|filtered is ambiguous, not confirmed open.

Interpreting Nmap port states including open, closed, filtered, and open|filtered

Choosing Nmap flags such as -sV, -sU, -sS, and -Pn for specific goals

Performing host discovery sweeps with -sn when ICMP echo is blocked

Understanding UDP scan challenges: no handshake, ICMP rate limiting, slow results

Watch out for

Common Scanning and Host Discovery exam traps

  • ▸Assuming open|filtered means the port is definitely open; it means Nmap cannot distinguish open from filtered, common with UDP or firewalled TCP.
  • ▸Forgetting -sV when the question asks for exact service version; a plain port scan only reports the port state.
  • ▸Using -sn for a sweep but expecting port results; -sn performs host discovery only and does not scan ports.

Question index

All Scanning and Host Discovery questions (17)

Click any question to see the full explanation, or start a practice session above.

1

You are performing a penetration test against a web server that is protected by a network-based intrusion prevention system (IPS). You need to conduct a port scan while minimizing the chance of being blocked. Which two Nmap options should you use to evade the IPS? (Choose two.)

Medium
2

You are performing a network audit and need to identify live hosts across a segmented network while minimizing the risk of triggering IDS alerts. Which Nmap technique is most appropriate for stealthy host discovery in a subnet where ICMP echo requests are filtered by the firewall?

Medium
3

You are performing a penetration test against a web server and want to identify the exact version of the HTTP service running on port 80. Which Nmap command should you use?

Easy
4

You are scanning a target that resides behind a firewall configured to drop TCP packets with the ACK flag set. You want to determine whether the firewall is stateful or stateless. Which Nmap scan type should you use to help make this determination by analyzing the responses to ACK packets?

Hard
5

When conducting a network scan, you notice that many hosts are not responding to ping requests, even though they are known to be online. What is the most appropriate Nmap flag to use to ensure these hosts are still scanned for open ports?

Easy
6

Refer to the exhibit. You executed an Nmap scan against a host and received the output shown. Which scanning technique was most likely used to produce this specific state-based output while avoiding the completion of a full TCP three-way handshake?

Hard
7

You are performing a penetration test and need to scan a large Class B network (10.0.0.0/16) for live hosts. You want to minimize the scan time while still getting accurate results. Which Nmap option should you use to perform a ping sweep without port scanning?

Easy
8

During an internal penetration test, you need to discover live hosts on a flat Layer 2 network segment. The client's IDS is known to alert on TCP SYN packets sent to closed ports. You want to minimize the chance of triggering an alert while still identifying as many hosts as possible. Which Nmap host discovery technique should you use?

Medium
9

You are scanning a target and need to avoid triggering a network IPS that signatures on TCP connect scans. You have root privileges and want to perform a stealthy scan that does not complete the TCP three-way handshake. Which Nmap scan type should you use?

Medium
10

During an internal penetration test you need to enumerate live hosts on a /24 subnet that you suspect is protected by a stateful firewall dropping ICMP echo requests. You want the scan to be fast and you have administrative (root) privileges on your Kali system. Which Nmap command best accomplishes host discovery in this scenario?

Medium
11

Refer to the exhibit. What is the primary purpose of the Nmap Scripting Engine (NSE) in the context of the output provided, and how does it improve upon standard port scanning?

Hard
12

You are performing a penetration test against a target that is behind a firewall configured to drop all TCP packets except those destined for port 443. You need to determine whether the firewall is stateful or stateless to plan your attack. Which Nmap scan technique will best help you make this determination?

Hard
13

Refer to the exhibit. What does the Nmap status 'open|filtered' indicate about the target port, and why does this result commonly occur in penetration testing scenarios?

Hard
14

You are scanning a target from a host on the same Ethernet segment. You run 'nmap -sS -p 445 192.168.1.50' and receive a response indicating the port is open. You then run the same scan from a different subnet across a router and receive no response at all, even though the service is confirmed running. Which statement best explains this difference?

Hard
15

You are performing a penetration test and need to identify all live hosts on a subnet without performing a port scan. Which Nmap command should you use to accomplish this?

Easy
16

During an internal penetration test, you need to sweep a /24 subnet for live hosts using Nmap. The client's security team has confirmed that ICMP echo requests are blocked at the host firewall on all workstations, but they want you to use a technique that still elicits responses from hosts that are up without relying on ICMP. Which Nmap host discovery option should you use to maximize host detection in this environment?

Medium
17

You are analyzing a target environment and need to identify UDP services. Which THREE of the following are significant challenges associated with performing an accurate UDP scan compared to a TCP scan?

Hard

Frequently asked questions

What does the Scanning and Host Discovery domain cover on the GPEN exam?
You must read Nmap output, pick the right scan flags, and explain port states. The key skill is matching the command to the objective: -sV for versions, -sU for UDP, -Pn to skip host discovery, and knowing open|filtered is ambiguous, not confirmed open.
How many questions are in this domain?
This page lists all 17 Scanning and Host Discovery questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Scanning and Host Discovery questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gpen GIAC-GPEN scanning and host discovery Practice Questions