Courseiva

GPEN Scanning and Host Discovery Practice Question

When conducting a network scan, you notice that many hosts are not responding to ping requests, even though they are known to be online. What is the most appropriate Nmap flag to use to ensure these hosts are still scanned for open ports?

⚠ Common exam trap

Candidates often confuse -Pn with -sS or -sV. They think -Pn is a scanning technique for ports, but it is strictly a host discovery bypass flag.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

-Pn (No ping)

The -Pn flag is the standard solution when hosts are configured to drop ICMP traffic. It forces Nmap to skip the host discovery phase and proceed directly to port scanning, assuming that every target is 'up'. This is a fundamental technique for penetration testers, as security-conscious organizations often disable ICMP at the perimeter to prevent basic discovery by automated tools and internal network scanning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    -sP (Ping scan)

    Why it's wrong here

    The -sP flag performs a ping scan, which is the very thing that is failing in this scenario. Using this flag will not help if the firewall or host is configured to drop ICMP echo requests; it will simply repeat the same failure encountered during initial discovery.

  • ✓

    -Pn (No ping)

    Why this is correct

    The -Pn flag instructs Nmap to treat all hosts as online. It skips the ping discovery phase entirely, allowing the scanner to attempt port probes on every target regardless of whether they respond to ICMP. This is necessary for scanning hosts that are protected by ICMP-blocking firewalls.

  • ✗

    -PR (ARP ping)

    Why it's wrong here

    ARP ping only works on the local network segment. If the targets are on a different subnet or behind a router, ARP traffic will not reach them. Therefore, this flag is not suitable for discovering hosts across network boundaries, as it is strictly limited to Layer 2.

  • ✗

    -sn (Disable port scan)

    Why it's wrong here

    The -sn flag disables port scanning entirely, performing only host discovery. Since the objective is to scan for open ports, disabling this phase is the opposite of the desired outcome. It would result in no port information being collected for any of the target hosts.

About these practice questions

Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.