GPEN Scanning and Host Discovery Practice Question
Exhibit
Starting Nmap 7.92 at 2023-10-01 10:00 UTC Nmap scan report for 192.168.1.10 Host is up (0.0012s latency). PORT STATE SERVICE 22/tcp open ssh 80/tcp open http 443/tcp open https
Refer to the exhibit. You executed an Nmap scan against a host and received the output shown. Which scanning technique was most likely used to produce this specific state-based output while avoiding the completion of a full TCP three-way handshake?
⚠ Common exam trap
Candidates often confuse SYN scans with full TCP connect scans (-sT), forgetting that SYN scans avoid completing the three-way handshake by sending an RST packet.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
TCP SYN Scan (-sS)
The output indicates open ports without explicitly showing a full connection. Nmap's SYN scan (-sS) is the default and most popular method for this result. It initiates the handshake but sends an RST packet immediately after receiving the SYN/ACK, preventing a full connection. This technique is essential for testers to map services quickly while remaining stealthier than a full connection-based scan which would be logged by most application-layer firewalls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
TCP Connect Scan (-sT)
Why it's wrong here
The TCP connect scan relies on the operating system's connect system call to complete the three-way handshake. Because this fully establishes a connection, it is easily logged by application servers and security appliances, making it distinct from the stealth-focused SYN scan that leaves connections incomplete at the target.
- ✓
TCP SYN Scan (-sS)
Why this is correct
The SYN scan is the 'half-open' technique that identifies open ports by initiating the handshake but never finishing it. By sending a RST packet upon receiving a SYN/ACK, it avoids creating a full connection entry in the target's socket table, which is the standard behavior for most Nmap scans.
- ✗
UDP Scan (-sU)
Why it's wrong here
UDP scanning is used to identify services running on the UDP protocol, such as DNS or DHCP. The output provided shows only TCP ports (22, 80, 443), and the state 'open' for UDP is determined by different logic, such as waiting for a response that rarely occurs.
- ✗
TCP ACK Scan (-sA)
Why it's wrong here
The ACK scan is used to map out firewall rulesets rather than identifying open ports. It does not produce an 'open' state in the same manner as a SYN scan, as it is designed to determine if ports are filtered or unfiltered based on the RST packet response behavior.
Visual reference
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.