GPEN Scanning and Host Discovery Practice Question
During an internal penetration test, you need to sweep a /24 subnet for live hosts using Nmap. The client's security team has confirmed that ICMP echo requests are blocked at the host firewall on all workstations, but they want you to use a technique that still elicits responses from hosts that are up without relying on ICMP. Which Nmap host discovery option should you use to maximize host detection in this environment?
⚠ Common exam trap
The trap here is assuming that a ping sweep must use ICMP, when TCP-based pings often succeed where ICMP is filtered.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
nmap -sn -PS22,80,443 10.10.10.0/24
A TCP SYN ping (-PS) to common ports like 22, 80, and 443 is effective when ICMP is blocked because it uses TCP handshake responses to determine host liveness. The -sn flag suppresses port scanning and focuses on discovery. This combination reliably identifies live hosts that would otherwise be missed by ICMP-based methods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
nmap -sn -PS22,80,443 10.10.10.0/24
Why this is correct
The -PS option performs a TCP SYN ping to the specified ports. Hosts that are up will respond with a SYN/ACK (if the port is open) or RST (if closed), allowing discovery even when ICMP is filtered. Combining -sn with -PS22,80,443 targets common open ports, making it highly effective in this scenario where ICMP is blocked.
- ✗
nmap -sn -PP 10.10.10.0/24
Why it's wrong here
-PP sends an ICMP timestamp request. Many firewalls and host-based filters block ICMP timestamp requests by default, and the scenario indicates ICMP is filtered. This option is less likely to succeed than a TCP-based ping because it relies on an ICMP type that is frequently disabled, resulting in incomplete host discovery.
- ✗
nmap -sn -PE 10.10.10.0/24
Why it's wrong here
-PE sends an ICMP echo request. Since the scenario states that ICMP echo requests are blocked on all workstations, this scan will likely miss live hosts. While -PE works on networks that permit ICMP, it is ineffective here because the host firewall drops those packets, leading to false negatives in host discovery.
- ✗
nmap -sn -PR 10.10.10.0/24
Why it's wrong here
-PR performs an ARP ping, which only works on the local Ethernet segment. If the /24 is not directly attached to your scanning host, ARP requests will not be routed and the scan will fail to discover remote hosts. Even on a local subnet, ARP may be blocked by some switch security features, though it is generally reliable locally.
Visual reference
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.