GPEN Scanning and Host Discovery Practice Question
Exhibit
Nmap scan report for 10.0.0.1 PORT STATE SERVICE 80/tcp open|filtered http
Refer to the exhibit. What does the Nmap status 'open|filtered' indicate about the target port, and why does this result commonly occur in penetration testing scenarios?
⚠ Common exam trap
Candidates often assume 'open|filtered' means the port is definitely open, ignoring that it is an indeterminate state caused by dropped packets, which prevents Nmap from confirming the port's true status.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The port is likely open but the scanner is not receiving a clear response.
The 'open|filtered' state means Nmap cannot determine if the port is open or filtered. This happens when the port sends no response to a probe, which is typical behavior for firewalls that drop packets rather than rejecting them. Understanding this distinction is critical for testers, as it implies that the port might be open but protected, necessitating further probing to determine the true state of the service behind the security boundary.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The port is definitely open but the response was malformed.
Why it's wrong here
The 'open|filtered' state does not mean the port is definitely open. It indicates ambiguity. Nmap simply cannot distinguish between a dropped packet (filtered) and a port that is open but not responding to the specific probe used. The data remains inconclusive for the tester.
- ✗
The port is likely closed and the firewall is silently dropping traffic.
Why it's wrong here
If the port were closed, Nmap would likely receive an RST packet or an ICMP unreachable message, labeling it as 'closed'. The 'open|filtered' result specifically points to a lack of response, which is a common symptom of a firewall that silently discards traffic without sending any denial packets.
- ✓
The port is likely open but the scanner is not receiving a clear response.
Why this is correct
This result occurs when Nmap sends a probe and receives no response. It could be that the port is open and the service is not replying, or that a firewall is filtering the traffic. The lack of feedback prevents Nmap from giving a definitive status, creating a state of uncertainty.
- ✗
The port is definitely filtered and the service is unreachable.
Why it's wrong here
Nmap only labels a port as 'filtered' if it receives an ICMP port unreachable message or if it is very sure the firewall is dropping traffic. 'Open|filtered' is reserved for when the status is genuinely unknown due to a complete lack of response from the target host's port.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.