GPEN Reconnaissance Practice Question
Why is it important to perform reconnaissance from a non-attributable source during a penetration test?
⚠ Common exam trap
Students mistakenly think non-attributable sources are meant to bypass encryption or increase scan speed, rather than protecting the tester's IP from being blocked by security alerts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To avoid triggering security alerts that block the tester's IP.
Using non-attributable sources, such as a VPN or a compromised proxy, prevents the target from tracing reconnaissance activities back to the testing firm or the specific tester. This protects the anonymity of the test, ensuring that the target's security response is triggered based on the activity itself, rather than by blocking a known testing IP. This is essential for simulating a realistic threat actor's behavior and avoiding early detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To improve the speed of data transfer during scans.
Why it's wrong here
Anonymity measures like VPNs or proxies typically introduce latency and reduce overall network throughput. They are used for security and operational secrecy, not for performance optimization. Using non-attributable sources is a tactical decision to maintain the stealth of the engagement, acknowledging that performance might be negatively impacted as a result.
- ✓
To avoid triggering security alerts that block the tester's IP.
Why this is correct
Organizations often monitor for scanning activity and blacklist source IPs associated with malicious behavior. By using non-attributable sources, the tester ensures that if one source is detected and blocked, the testing engagement can continue from another, thus preventing a single block from prematurely ending the reconnaissance phase.
- ✗
To bypass the need for explicit written authorization.
Why it's wrong here
Anonymity does not replace the requirement for legal authorization. All penetration testing must be conducted under a strict contract. Anonymity is a tool for professional practice, not a mechanism to bypass legal or ethical requirements. Regardless of the source IP, the tester must have written permission to perform actions.
- ✗
To increase the accuracy of vulnerability detection tools.
Why it's wrong here
The accuracy of scanning tools is determined by the tool configuration and the target's response, not the source IP. Using an anonymous proxy does not improve the tool's ability to identify vulnerabilities; in fact, it may cause issues if the proxy alters packet headers or disrupts the TCP handshake process.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.