Courseiva
Scanning and Host Discovery →mediumMultiple Select

GPEN Scanning and Host Discovery Practice Question

You are performing a penetration test against a web server that is protected by a network-based intrusion prevention system (IPS). You need to conduct a port scan while minimizing the chance of being blocked. Which two Nmap options should you use to evade the IPS? (Choose two.)

⚠ Common exam trap

The trap here is thinking that adding more scan features like version or OS detection will help evade detection, when they actually increase the scan's footprint.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use -T0 or -T1 to slow down the scan.

To evade an IPS during a port scan, slowing down the scan with -T0 or -T1 and using decoys with -D RND:10 are effective techniques. These methods reduce the scan's signature and make it harder for the IPS to correlate the activity to a single source, thereby minimizing the risk of being blocked.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use -T0 or -T1 to slow down the scan.

    Why this is correct

    The -T0 (Paranoid) and -T1 (Sneaky) timing templates drastically reduce the scan speed, sending packets with long delays between them. This makes the scan traffic less likely to trigger rate-based IPS signatures, which often flag rapid port scans. Slowing down is a classic evasion technique that helps avoid detection by network security devices.

  • ✓

    Use -D RND:10 to decoy the scan.

    Why this is correct

    The -D option enables decoy scanning, where Nmap sends packets from multiple spoofed source IP addresses in addition to your own. Using RND:10 generates 10 random decoy IPs. This confuses the IPS and makes it harder to attribute the scan to your real IP, reducing the likelihood of being blocked. It is an effective evasion method when used with other techniques.

  • ✗

    Use -O to enable OS detection.

    Why it's wrong here

    OS detection (-O) sends a series of TCP and UDP probes with unusual flag combinations and payloads. These are often flagged by IPS signatures as suspicious. Enabling OS detection during a scan increases the likelihood of triggering the IPS, making it counterproductive for evasion. It should be avoided when trying to remain stealthy.

  • ✗

    Use -A to enable aggressive scan options.

    Why it's wrong here

    The -A flag enables OS detection, version detection, script scanning, and traceroute. This aggressive scanning generates a lot of traffic and uses many probes that IPS systems are designed to detect. It is the opposite of stealthy and would almost certainly trigger the IPS, leading to your IP being blocked.

  • ✗

    Use -sV to enable version detection.

    Why it's wrong here

    Version detection (-sV) sends additional probes to identify service versions, which increases the volume and variety of traffic. This can actually make the scan more conspicuous and more likely to trigger IPS signatures. It does not help evade detection; instead, it may increase the chance of being blocked by the IPS.

About these practice questions

Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.