Courseiva
Scanning and Host Discovery →mediumMultiple Choice

GPEN Scanning and Host Discovery Practice Question

You are performing a network audit and need to identify live hosts across a segmented network while minimizing the risk of triggering IDS alerts. Which Nmap technique is most appropriate for stealthy host discovery in a subnet where ICMP echo requests are filtered by the firewall?

⚠ Common exam trap

Candidates often select ICMP-based discovery methods, forgetting that firewalls frequently block ICMP, which makes TCP SYN ping a more reliable and stealthy alternative for host discovery in segmented networks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Utilize TCP SYN ping (-PS) on common service ports.

Nmap's TCP SYN ping (-PS) is highly effective because it sends a small SYN packet to specified ports, like 80 or 443, which are typically open or acknowledged by firewalls. This bypasses ICMP filters while mimicking legitimate traffic. Understanding how to circumvent basic perimeter defenses is critical for penetration testers to ensure comprehensive discovery without alerting security systems that monitor for common ICMP-based scanning patterns or heavy traffic floods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Perform a standard ICMP echo sweep (-PE).

    Why it's wrong here

    Standard ICMP echo requests are explicitly blocked by the firewall in the scenario provided. Relying on ICMP will result in zero discovery across the subnet, as the firewall drops these packets before they reach the target hosts, causing the scan to fail to identify any active machines.

  • ✗

    Execute a full TCP connect scan on all ports (-sT).

    Why it's wrong here

    A full TCP connect scan completes the three-way handshake and is easily logged by most host-based and network-based intrusion detection systems. This approach is highly noisy and the opposite of stealthy, making it a poor choice when the objective is to maintain a low profile during discovery.

  • ✓

    Utilize TCP SYN ping (-PS) on common service ports.

    Why this is correct

    TCP SYN ping sends a SYN packet to common ports, effectively bypassing ICMP-only filters. Because it does not complete a full three-way handshake, it is significantly stealthier than a full TCP connect scan. This technique is a standard industry method for host discovery in hardened, filtered network environments.

  • ✗

    Run an ARP scan across the entire subnet (-PR).

    Why it's wrong here

    ARP scanning only functions on the local network segment where the attacker is directly connected at Layer 2. If the scan needs to pass through routers or firewalls to reach segmented networks, ARP traffic will be dropped at the gateway, rendering this method useless for multi-segment discovery.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.