GPEN Vulnerability Scanning Practice Question
What is the primary purpose of a 'delta' or 'differential' vulnerability scan?
⚠ Common exam trap
Candidates often confuse delta scans with full vulnerability audits, mistakenly believing they are meant to discover all vulnerabilities rather than specifically focusing on identifying changes since the last assessment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To identify only the changes in the vulnerability posture since the last scan.
Delta scans focus on identifying changes in the environment since the last full assessment. By comparing current findings against a known baseline, testers can quickly isolate new vulnerabilities or unauthorized changes. This is vital for maintaining a continuous security posture, as it reduces scan times and allows security teams to prioritize remediation efforts on newly introduced risks without re-analyzing the entire stable environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To increase the intensity of the scan to ensure all ports are covered.
Why it's wrong here
Delta scans are designed for efficiency, not increased intensity. Increasing scan intensity usually involves full port scans or aggressive fuzzing, which are the opposite of the time-saving purpose of a differential scan. Their goal is to identify changes, not to exhaustively re-test the entire infrastructure.
- ✓
To identify only the changes in the vulnerability posture since the last scan.
Why this is correct
Differential scans compare the results of the current scan to a baseline, highlighting only what has been added, removed, or changed. This allows administrators to track new vulnerabilities introduced by recent updates or configuration changes without wasting resources re-scanning systems that have not changed state.
- ✗
To bypass signature-based detection systems by using randomized payloads.
Why it's wrong here
Bypassing detection systems is an evasion technique rather than a vulnerability management process. Delta scans focus on the state of the target system's vulnerabilities, not on obfuscating the scanner's traffic to avoid being detected by network security monitoring tools or intrusion detection systems.
- ✗
To perform an exhaustive search for zero-day vulnerabilities on all assets.
Why it's wrong here
Zero-day detection is not the primary function of delta scans, as zero-day vulnerabilities are inherently unknown to the scanner's signature database. Delta scans simply identify status changes for known vulnerabilities, whereas zero-day detection requires behavioral analysis or advanced fuzzing techniques that go beyond delta comparisons.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.