GPEN Reconnaissance Practice Question
You are conducting a penetration test and have gained access to a target's internal network. You want to perform reconnaissance to identify other live hosts and services without using traditional port scanning that might trigger IDS alerts. Which of the following techniques would be most effective for low-noise host discovery on the internal network?
⚠ Common exam trap
The trap here is assuming that any scan with nmap is stealthy, but on a local network, ARP scanning is far less likely to trigger alerts than TCP or ICMP-based scans.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ARP scanning using arp-scan
ARP scanning is a Layer 2 technique that discovers live hosts by sending ARP requests. Since ARP is essential for local network communication, it is rarely filtered or monitored by IDS. This makes it a stealthy and effective method for internal host discovery. The other techniques involve IP or TCP/UDP packets that can be detected or blocked, making them less suitable for low-noise reconnaissance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
TCP SYN scan using nmap
Why it's wrong here
TCP SYN scans are active and can be detected by IDS and firewalls. They send SYN packets to many ports, which may trigger alerts. While effective for port scanning, they are not the best choice for low-noise host discovery, especially when trying to avoid detection.
- ✗
UDP scan using nmap
Why it's wrong here
UDP scans are unreliable and slow, and they can also trigger IDS alerts. They do not provide a stealthy method for host discovery. Additionally, many hosts do not respond to UDP probes, making it inefficient for identifying live hosts.
- ✓
ARP scanning using arp-scan
Why this is correct
ARP scanning sends ARP requests to all IPs in a subnet. Since ARP is a Layer 2 protocol, it does not traverse routers and is not typically monitored by IDS. It is fast, accurate, and stealthy for discovering live hosts on the local subnet. This makes it ideal for low-noise internal reconnaissance.
- ✗
ICMP ping sweep using fping
Why it's wrong here
ICMP ping sweeps are often blocked by firewalls and can be detected by IDS. They generate ICMP traffic that may trigger alerts. While fping is efficient, it is not as stealthy as ARP scanning on a local network, where ARP is necessary for communication and less likely to be flagged.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.