Courseiva
Reconnaissance →hardMultiple Choice

GPEN Reconnaissance Practice Question

You are conducting a penetration test and have gained access to a target's internal network. You want to perform reconnaissance to identify other live hosts and services without using traditional port scanning that might trigger IDS alerts. Which of the following techniques would be most effective for low-noise host discovery on the internal network?

⚠ Common exam trap

The trap here is assuming that any scan with nmap is stealthy, but on a local network, ARP scanning is far less likely to trigger alerts than TCP or ICMP-based scans.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ARP scanning using arp-scan

ARP scanning is a Layer 2 technique that discovers live hosts by sending ARP requests. Since ARP is essential for local network communication, it is rarely filtered or monitored by IDS. This makes it a stealthy and effective method for internal host discovery. The other techniques involve IP or TCP/UDP packets that can be detected or blocked, making them less suitable for low-noise reconnaissance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    TCP SYN scan using nmap

    Why it's wrong here

    TCP SYN scans are active and can be detected by IDS and firewalls. They send SYN packets to many ports, which may trigger alerts. While effective for port scanning, they are not the best choice for low-noise host discovery, especially when trying to avoid detection.

  • ✗

    UDP scan using nmap

    Why it's wrong here

    UDP scans are unreliable and slow, and they can also trigger IDS alerts. They do not provide a stealthy method for host discovery. Additionally, many hosts do not respond to UDP probes, making it inefficient for identifying live hosts.

  • ✓

    ARP scanning using arp-scan

    Why this is correct

    ARP scanning sends ARP requests to all IPs in a subnet. Since ARP is a Layer 2 protocol, it does not traverse routers and is not typically monitored by IDS. It is fast, accurate, and stealthy for discovering live hosts on the local subnet. This makes it ideal for low-noise internal reconnaissance.

  • ✗

    ICMP ping sweep using fping

    Why it's wrong here

    ICMP ping sweeps are often blocked by firewalls and can be detected by IDS. They generate ICMP traffic that may trigger alerts. While fping is efficient, it is not as stealthy as ARP scanning on a local network, where ARP is necessary for communication and less likely to be flagged.

About these practice questions

Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.