GPEN · domain
Scanning and Host Discovery
This domain covers Nmap-driven host discovery and port scanning: interpreting port states like open|filtered, selecting scan types (SYN, UDP, version detection), and sweeping subnets when ICMP is blocked. GPEN questions present scenarios with exhibits or command output and require you to choose correct Nmap syntax and explain scan behavior and limitations.
Focused practice
Practice Scanning and Host Discovery questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Scanning and Host Discovery
You must read Nmap output, pick the right scan flags, and explain port states. The key skill is matching the command to the objective: -sV for versions, -sU for UDP, -Pn to skip host discovery, and knowing open|filtered is ambiguous, not confirmed open.
Watch out for
Common Scanning and Host Discovery exam traps
- ▸Assuming open|filtered means the port is definitely open; it means Nmap cannot distinguish open from filtered, common with UDP or firewalled TCP.
- ▸Forgetting -sV when the question asks for exact service version; a plain port scan only reports the port state.
- ▸Using -sn for a sweep but expecting port results; -sn performs host discovery only and does not scan ports.
Question index
All Scanning and Host Discovery questions (17)
Click any question to see the full explanation, or start a practice session above.
You are performing a penetration test against a web server that is protected by a network-based intrusion prevention system (IPS). You need to conduct a port scan while minimizing the chance of being blocked. Which two Nmap options should you use to evade the IPS? (Choose two.)
Medium2You are performing a network audit and need to identify live hosts across a segmented network while minimizing the risk of triggering IDS alerts. Which Nmap technique is most appropriate for stealthy host discovery in a subnet where ICMP echo requests are filtered by the firewall?
Medium3You are performing a penetration test against a web server and want to identify the exact version of the HTTP service running on port 80. Which Nmap command should you use?
Easy4You are scanning a target that resides behind a firewall configured to drop TCP packets with the ACK flag set. You want to determine whether the firewall is stateful or stateless. Which Nmap scan type should you use to help make this determination by analyzing the responses to ACK packets?
Hard5When conducting a network scan, you notice that many hosts are not responding to ping requests, even though they are known to be online. What is the most appropriate Nmap flag to use to ensure these hosts are still scanned for open ports?
Easy6Refer to the exhibit. You executed an Nmap scan against a host and received the output shown. Which scanning technique was most likely used to produce this specific state-based output while avoiding the completion of a full TCP three-way handshake?
Hard7You are performing a penetration test and need to scan a large Class B network (10.0.0.0/16) for live hosts. You want to minimize the scan time while still getting accurate results. Which Nmap option should you use to perform a ping sweep without port scanning?
Easy8During an internal penetration test, you need to discover live hosts on a flat Layer 2 network segment. The client's IDS is known to alert on TCP SYN packets sent to closed ports. You want to minimize the chance of triggering an alert while still identifying as many hosts as possible. Which Nmap host discovery technique should you use?
Medium9You are scanning a target and need to avoid triggering a network IPS that signatures on TCP connect scans. You have root privileges and want to perform a stealthy scan that does not complete the TCP three-way handshake. Which Nmap scan type should you use?
Medium10During an internal penetration test you need to enumerate live hosts on a /24 subnet that you suspect is protected by a stateful firewall dropping ICMP echo requests. You want the scan to be fast and you have administrative (root) privileges on your Kali system. Which Nmap command best accomplishes host discovery in this scenario?
Medium11Refer to the exhibit. What is the primary purpose of the Nmap Scripting Engine (NSE) in the context of the output provided, and how does it improve upon standard port scanning?
Hard12You are performing a penetration test against a target that is behind a firewall configured to drop all TCP packets except those destined for port 443. You need to determine whether the firewall is stateful or stateless to plan your attack. Which Nmap scan technique will best help you make this determination?
Hard13Refer to the exhibit. What does the Nmap status 'open|filtered' indicate about the target port, and why does this result commonly occur in penetration testing scenarios?
Hard14You are scanning a target from a host on the same Ethernet segment. You run 'nmap -sS -p 445 192.168.1.50' and receive a response indicating the port is open. You then run the same scan from a different subnet across a router and receive no response at all, even though the service is confirmed running. Which statement best explains this difference?
Hard15You are performing a penetration test and need to identify all live hosts on a subnet without performing a port scan. Which Nmap command should you use to accomplish this?
Easy16During an internal penetration test, you need to sweep a /24 subnet for live hosts using Nmap. The client's security team has confirmed that ICMP echo requests are blocked at the host firewall on all workstations, but they want you to use a technique that still elicits responses from hosts that are up without relying on ICMP. Which Nmap host discovery option should you use to maximize host detection in this environment?
Medium17You are analyzing a target environment and need to identify UDP services. Which THREE of the following are significant challenges associated with performing an accurate UDP scan compared to a TCP scan?
HardOther domains
All GPEN exam domains
Frequently asked questions
- What does the Scanning and Host Discovery domain cover on the GPEN exam?
- You must read Nmap output, pick the right scan flags, and explain port states. The key skill is matching the command to the objective: -sV for versions, -sU for UDP, -Pn to skip host discovery, and knowing open|filtered is ambiguous, not confirmed open.
- How many questions are in this domain?
- This page lists all 17 Scanning and Host Discovery questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Scanning and Host Discovery questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.