Courseiva

GPEN · topic practice

Vulnerability Scanning practice questions

This domain covers planning, executing, and interpreting vulnerability scans within authorized engagements. GPEN tests your ability to scope scans via rules of engagement, configure authenticated scanning with least-privilege credentials, tune Nmap UDP scanning to resolve open|filtered ambiguity, and rank findings by exploitability and asset criticality rather than raw CVSS alone.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Vulnerability Scanning

What the exam tests

What to know about Vulnerability Scanning

You must plan scans against the signed scope, run Nmap UDP scans that distinguish open from filtered, configure least-privilege authenticated scans, and rank vulnerabilities by exploitability plus asset value. The single most important thing: never scan outside the authorized scope defined in the rules of engagement.

Reading rules of engagement and scope documents before any scanning activity begins

Using Nmap UDP scans with version detection and timing options to classify open|filtered ports

Configuring authenticated Windows scans with least-privilege service or domain accounts

Prioritizing findings using CVSS, exploit availability, asset exposure, and business criticality

Watch out for

Common Vulnerability Scanning exam traps

  • ▸Scanning outside the authorized scope or before confirming rules of engagement, which invalidates the engagement regardless of findings
  • ▸Treating open|filtered UDP results as confirmed open ports instead of retrying with version detection or ICMP responses
  • ▸Using domain administrator credentials for authenticated scans when a limited read-only account would suffice

Practice set

Vulnerability Scanning questions

20 questions · select your answer, then reveal the explanation

Which THREE of the following are primary causes for high false-positive rates in automated vulnerability scanning?

Which TWO of the following should be considered when selecting a vulnerability scanning window for a production environment?

During a scan, you notice that a specific host is consistently marked as 'down' despite being reachable via ping. What is the most likely cause?

Refer to the exhibit. The scan is taking significantly longer than expected. Which configuration change will most effectively increase the speed without causing network instability?

Exhibit

{
  "policy": "strict",
  "depth": "full",
  "timeout_ms": 500,
  "max_concurrent_hosts": 10,
  "threads_per_host": 5
}

Which THREE of the following are benefits of performing authenticated scans instead of unauthenticated scans?

A vulnerability scanner is unable to authenticate to a Linux target despite providing correct SSH credentials. What is the most common reason for this failure in a hardened environment?

When scanning a segmented network, why is it recommended to place the scanner inside each segment rather than scanning through a firewall?

A penetration tester is performing an authenticated vulnerability scan against a Windows Server 2019 target using Tenable Nessus. The scan completes successfully but reports only a handful of informational findings, far fewer than expected given the server's outdated patch level. The tester verifies that the credentials are valid and that the Nessus service account has local administrator rights. Which configuration setting is the MOST likely cause of the limited results?

A penetration tester is configuring an authenticated scan for a Windows environment. Which credential management strategy best minimizes the security impact while maintaining scan efficacy?

Refer to the exhibit. An Nmap scan returns output indicating a web server is responding, but the `http-enum` script fails to identify common directories. Which action should the tester take to improve detection?

Network Topology
nmap -sV -p 80script=http-enum

What is the primary purpose of a 'delta' or 'differential' vulnerability scan?

Which phase of a vulnerability assessment typically involves comparing the output against a known database of CVEs?

Which of the following actions is the most appropriate step after discovering a critical vulnerability that is currently being exploited in the wild?

Which document should a penetration tester consult to determine the allowed scope and rules of engagement for a vulnerability scan?

Question 15mediummulti select
Review the full subnetting walkthrough →

A penetration tester is preparing to run a credentialed vulnerability scan against a mixed environment of Windows Server 2019 and Ubuntu 20.04 hosts on an internal /24 subnet. The tester wants to reduce scan duration and network load while still detecting missing patches and misconfigurations. Which two scanning techniques should the tester implement to achieve these goals? (Choose two.)

During a vulnerability scan of a web application, the scanner reports a critical SQL injection vulnerability on a login form. A manual test using a single quote in the username field returns a generic error page with no database details. The scanner's evidence shows a time-based blind SQL injection payload that caused a five-second delay. Which action should the penetration tester take next to validate the finding?

Question 17mediummultiple choice
Review the full subnetting walkthrough →

A penetration tester is using Nessus to scan a large subnet and needs to avoid overwhelming older printers that are known to crash when too many simultaneous connections are made. The tester also wants to ensure the scan completes in a reasonable timeframe. Which Nessus scan policy setting should be adjusted to control the number of simultaneous hosts being scanned?

A penetration tester is configuring a vulnerability scanner to assess a sensitive production network. The tester wants to avoid causing service disruptions or overwhelming network devices. Which scanner setting should be adjusted to best achieve this?

During a penetration test, a tester runs an OpenVAS scan against a web server and receives a report indicating a high-severity vulnerability with a CVE identifier. Before including it in the final report, the tester wants to verify if the vulnerability is actually exploitable. Which action should the tester take next?

A penetration tester is analyzing the results of a vulnerability scan and needs to prioritize remediation efforts. Which two factors should be considered when determining the criticality of a vulnerability? (Choose two.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Vulnerability Scanning sessions

Start a Vulnerability Scanning only practice session

Every question in these sessions is drawn from the Vulnerability Scanning domain — nothing else.

Related practice questions

Related GPEN topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GPEN exam test about Vulnerability Scanning?
You must plan scans against the signed scope, run Nmap UDP scans that distinguish open from filtered, configure least-privilege authenticated scans, and rank vulnerabilities by exploitability plus asset value. The single most important thing: never scan outside the authorized scope defined in the rules of engagement.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Vulnerability Scanning questions in a focused session?
Yes — the session launcher on this page draws every question from the Vulnerability Scanning domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GPEN topics?
Use the topic links above to move to related areas, or go back to the GPEN question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GPEN exam covers. They are not copied from any real exam or dump site.