Courseiva

GPEN Scanning and Host Discovery Practice Question

Exhibit

Starting Nmap 7.92 at 2023-10-01 10:00 UTC
Nmap scan report for 192.168.1.10
Host is up (0.0012s latency).
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http
443/tcp open https

Refer to the exhibit. You executed an Nmap scan against a host and received the output shown. Which scanning technique was most likely used to produce this specific state-based output while avoiding the completion of a full TCP three-way handshake?

⚠ Common exam trap

Candidates often confuse SYN scans with full TCP connect scans (-sT), forgetting that SYN scans avoid completing the three-way handshake by sending an RST packet.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

TCP SYN Scan (-sS)

The output indicates open ports without explicitly showing a full connection. Nmap's SYN scan (-sS) is the default and most popular method for this result. It initiates the handshake but sends an RST packet immediately after receiving the SYN/ACK, preventing a full connection. This technique is essential for testers to map services quickly while remaining stealthier than a full connection-based scan which would be logged by most application-layer firewalls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    TCP Connect Scan (-sT)

    Why it's wrong here

    The TCP connect scan relies on the operating system's connect system call to complete the three-way handshake. Because this fully establishes a connection, it is easily logged by application servers and security appliances, making it distinct from the stealth-focused SYN scan that leaves connections incomplete at the target.

  • ✓

    TCP SYN Scan (-sS)

    Why this is correct

    The SYN scan is the 'half-open' technique that identifies open ports by initiating the handshake but never finishing it. By sending a RST packet upon receiving a SYN/ACK, it avoids creating a full connection entry in the target's socket table, which is the standard behavior for most Nmap scans.

  • ✗

    UDP Scan (-sU)

    Why it's wrong here

    UDP scanning is used to identify services running on the UDP protocol, such as DNS or DHCP. The output provided shows only TCP ports (22, 80, 443), and the state 'open' for UDP is determined by different logic, such as waiting for a response that rarely occurs.

  • ✗

    TCP ACK Scan (-sA)

    Why it's wrong here

    The ACK scan is used to map out firewall rulesets rather than identifying open ports. It does not produce an 'open' state in the same manner as a SYN scan, as it is designed to determine if ports are filtered or unfiltered based on the RST packet response behavior.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.