Courseiva

GPEN · domain

Vulnerability Scanning

This domain covers planning, executing, and interpreting vulnerability scans within authorized engagements. GPEN tests your ability to scope scans via rules of engagement, configure authenticated scanning with least-privilege credentials, tune Nmap UDP scanning to resolve open|filtered ambiguity, and rank findings by exploitability and asset criticality rather than raw CVSS alone.

22 questions5 easy10 medium7 hard

Focused practice

Practice Vulnerability Scanning questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Vulnerability Scanning

You must plan scans against the signed scope, run Nmap UDP scans that distinguish open from filtered, configure least-privilege authenticated scans, and rank vulnerabilities by exploitability plus asset value. The single most important thing: never scan outside the authorized scope defined in the rules of engagement.

Reading rules of engagement and scope documents before any scanning activity begins

Using Nmap UDP scans with version detection and timing options to classify open|filtered ports

Configuring authenticated Windows scans with least-privilege service or domain accounts

Prioritizing findings using CVSS, exploit availability, asset exposure, and business criticality

Watch out for

Common Vulnerability Scanning exam traps

  • ▸Scanning outside the authorized scope or before confirming rules of engagement, which invalidates the engagement regardless of findings
  • ▸Treating open|filtered UDP results as confirmed open ports instead of retrying with version detection or ICMP responses
  • ▸Using domain administrator credentials for authenticated scans when a limited read-only account would suffice

Question index

All Vulnerability Scanning questions (22)

Click any question to see the full explanation, or start a practice session above.

1

A penetration tester is using Nessus to scan a large subnet and needs to avoid overwhelming older printers that are known to crash when too many simultaneous connections are made. The tester also wants to ensure the scan completes in a reasonable timeframe. Which Nessus scan policy setting should be adjusted to control the number of simultaneous hosts being scanned?

Medium
2

A penetration tester is preparing to run a credentialed vulnerability scan against a mixed environment of Windows Server 2019 and Ubuntu 20.04 hosts on an internal /24 subnet. The tester wants to reduce scan duration and network load while still detecting missing patches and misconfigurations. Which two scanning techniques should the tester implement to achieve these goals? (Choose two.)

Medium
3

A penetration tester has completed an unauthenticated vulnerability scan of a web server and received a report listing several critical CVEs. Before including these in the final report, the tester wants to validate that the findings are not false positives. Which action is the MOST appropriate next step?

Easy
4

Which phase of a vulnerability assessment typically involves comparing the output against a known database of CVEs?

Medium
5

During a vulnerability scan of a web application, the scanner reports a critical SQL injection vulnerability on a login form. A manual test using a single quote in the username field returns a generic error page with no database details. The scanner's evidence shows a time-based blind SQL injection payload that caused a five-second delay. Which action should the penetration tester take next to validate the finding?

Hard
6

What is the primary purpose of a 'delta' or 'differential' vulnerability scan?

Easy
7

A penetration tester is conducting a vulnerability scan against a web application and notices that the scanner reports a critical SQL injection vulnerability on a page that does not accept user input. The tester manually verifies the page and finds no input fields or parameters. What is the most likely cause of this false positive?

Medium
8

A penetration tester is planning a vulnerability scan of a network that includes legacy systems and IoT devices. The tester needs to minimize the risk of disrupting these fragile devices while still gathering useful vulnerability data. Which two actions should the tester take? (Choose two.)

Hard
9

A penetration tester is using Nmap with the NSE script 'vulners' to identify vulnerabilities on a target. The scan returns a list of CVEs for detected services, but the tester notices that some CVEs have a low confidence score. What is the MOST accurate interpretation of these low-confidence findings?

Hard
10

A penetration tester needs to scan a large enterprise network for vulnerabilities but has only a short maintenance window. The tester wants to maximize scan coverage while minimizing the impact on production systems. Which Nessus scan policy setting should the tester adjust to balance speed and accuracy?

Medium
11

Refer to the exhibit. An Nmap scan returns output indicating a web server is responding, but the `http-enum` script fails to identify common directories. Which action should the tester take to improve detection?

Medium
12

During a penetration test, a tester runs an OpenVAS scan against a web server and receives a report indicating a high-severity vulnerability with a CVE identifier. Before including it in the final report, the tester wants to verify if the vulnerability is actually exploitable. Which action should the tester take next?

Hard
13

Which of the following actions is the most appropriate step after discovering a critical vulnerability that is currently being exploited in the wild?

Medium
14

A penetration tester is configuring a vulnerability scanner to assess a sensitive production network. The tester wants to avoid causing service disruptions or overwhelming network devices. Which scanner setting should be adjusted to best achieve this?

Easy
15

A penetration tester is using Nmap to scan a target subnet and wants to identify all hosts that are up without performing port scanning. The tester also wants to avoid sending TCP SYN packets to reduce noise. Which Nmap option should the tester use?

Hard
16

A penetration tester is reviewing the results of a vulnerability scan and sees a finding labeled 'SSL Certificate Expired' on a web server. The tester confirms that the certificate is indeed expired. What is the most appropriate next step according to typical penetration testing methodology?

Easy
17

Which document should a penetration tester consult to determine the allowed scope and rules of engagement for a vulnerability scan?

Easy
18

A penetration tester is using Nmap to scan a target network and wants to identify open UDP ports. The tester runs a UDP scan but notices that many ports are reported as 'open|filtered'. Which technique can help determine whether these ports are actually open or filtered?

Hard
19

A penetration tester is analyzing the results of a vulnerability scan and needs to prioritize remediation efforts. Which two factors should be considered when determining the criticality of a vulnerability? (Choose two.)

Medium
20

A penetration tester is configuring an authenticated scan for a Windows environment. Which credential management strategy best minimizes the security impact while maintaining scan efficacy?

Medium
21

A penetration tester is configuring a vulnerability scan against a large enterprise network. The tester needs to balance scan accuracy, speed, and impact on production systems. Which TWO of the following settings, when adjusted, will MOST directly reduce the risk of disrupting fragile network devices during the scan? (Choose two.)

Hard
22

A penetration tester is preparing to scan a network that includes a mix of traditional IT systems and industrial control systems (ICS). The tester wants to minimize the risk of disrupting ICS devices. Which scanning approach is MOST appropriate for the ICS segment?

Medium

Frequently asked questions

What does the Vulnerability Scanning domain cover on the GPEN exam?
You must plan scans against the signed scope, run Nmap UDP scans that distinguish open from filtered, configure least-privilege authenticated scans, and rank vulnerabilities by exploitability plus asset value. The single most important thing: never scan outside the authorized scope defined in the rules of engagement.
How many questions are in this domain?
This page lists all 22 Vulnerability Scanning questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Vulnerability Scanning questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gpen GIAC-GPEN vulnerability scanning Practice Questions