GPEN Vulnerability Scanning Practice Question
Network Topology
Refer to the exhibit. An Nmap scan returns output indicating a web server is responding, but the `http-enum` script fails to identify common directories. Which action should the tester take to improve detection?
⚠ Common exam trap
Candidates assume Nmap's default scripts are exhaustive. They often suggest running more Nmap scripts, failing to realize that specialized tools are required for effective web directory brute-forcing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a specialized web discovery tool like ffuf or Gobuster with a large wordlist.
The current command lacks service-specific depth. Adding a more comprehensive script category or using a specialized tool like Dirbuster or Burp Suite allows for brute-forcing against common file paths. Service version detection and enumeration scripts in Nmap are limited by the wordlist provided. Improving detection requires moving beyond passive enumeration into active path discovery, which is essential for identifying hidden administrative interfaces or unlinked configuration files.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the timing template to -T5 to make the scan faster.
Why it's wrong here
Increasing the timing template to -T5 focuses on speed and often causes missed packets or dropped connections due to congestion. It does not improve the accuracy of script-based directory enumeration and could lead to server-side rate limiting that blocks the scanner entirely.
- ✗
Add the --script-args='http-enum.basepath=/admin' argument to the command.
Why it's wrong here
Specifying a basepath forces the script to search only from that specific directory, which likely misses all other common locations. This narrows the scope incorrectly, as the goal is to discover unknown directories rather than verify a known one through brute-force enumeration.
- ✓
Use a specialized web discovery tool like ffuf or Gobuster with a large wordlist.
Why this is correct
Nmap's http-enum script uses a relatively small, hardcoded wordlist. Dedicated tools like Gobuster or ffuf allow for custom, extensive wordlists and high-concurrency requests, which are far more effective at discovering hidden web directories that Nmap scripts would overlook in a standard scan.
- ✗
Change the scan to -sS to perform a stealthy SYN scan instead of service detection.
Why it's wrong here
An -sS scan performs port discovery but does not interact with the web server application layer. Since the goal is to identify directories, which are an application-level concern, switching to a transport-layer SYN scan will provide less information about the web application structure.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.