Courseiva
Scanning and Host Discovery →mediumMultiple Choice

GPEN Scanning and Host Discovery Practice Question

You are scanning a target and need to avoid triggering a network IPS that signatures on TCP connect scans. You have root privileges and want to perform a stealthy scan that does not complete the TCP three-way handshake. Which Nmap scan type should you use?

⚠ Common exam trap

The trap here is assuming that any scan without root or any scan type is stealthy, when the key distinction is whether the TCP handshake is completed, which the SYN scan avoids.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

nmap -sS <target>

The TCP SYN scan sends a SYN packet and waits for a SYN/ACK or RST response, never completing the three-way handshake. This half-open approach is faster and stealthier than a full connect scan, making it the preferred method to evade IPS signatures that look for completed TCP connections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    nmap -sS <target>

    Why this is correct

    A TCP SYN scan (-sS), also known as a half-open scan, sends a SYN packet and analyzes the response without completing the handshake. It is fast, stealthy, and less likely to be logged by the target application. Since you have root privileges, this is the appropriate choice to avoid IPS signatures associated with full connections.

  • ✗

    nmap -sT <target>

    Why it's wrong here

    A TCP connect scan (-sT) completes the full three-way handshake using the operating system's connect() call. This makes it easily detected by IPS and IDS systems and leaves connection logs on the target. It is the default when running without root, but it is not stealthy and does not meet the requirement.

  • ✗

    nmap -sU <target>

    Why it's wrong here

    A UDP scan (-sU) targets UDP ports and does not establish TCP connections at all. It is slow, often unreliable due to ICMP rate limiting, and irrelevant if the goal is to stealthily scan TCP services. It does not address the requirement of avoiding a TCP connect scan signature.

  • ✗

    nmap -sA <target>

    Why it's wrong here

    A TCP ACK scan (-sA) is used to map firewall rules and determine whether ports are filtered, not to discover open TCP services. It sends ACK packets and interprets RST responses, but it cannot distinguish open from closed ports. It is not a stealthy port scanning technique for identifying open services.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.