Courseiva

GPEN Scanning and Host Discovery Practice Question

You are scanning a target from a host on the same Ethernet segment. You run 'nmap -sS -p 445 192.168.1.50' and receive a response indicating the port is open. You then run the same scan from a different subnet across a router and receive no response at all, even though the service is confirmed running. Which statement best explains this difference?

⚠ Common exam trap

The trap here is blaming the scan type for a routing or filtering issue, when SYN scans work fine across routers and the real cause is usually an intermediate firewall or ACL.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A firewall or ACL between the subnets is blocking TCP/445, so the SYN packets never reach the target or the responses never return, resulting in a filtered or no-response state.

The discrepancy between local and remote scan results points to a network-level filter rather than a scanning limitation. SYN scans are routable, so when TCP/445 is reachable on the LAN but silent across a router, an intermediate firewall or ACL is the most probable cause of the filtered result.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The SYN scan relies on receiving a RST or SYN/ACK, but the router may be filtering or dropping the return traffic, causing the port to appear filtered from the remote subnet.

    Why it's wrong here

    This is partially plausible but incomplete: the more specific cause is that SYN scanning works at layer 3/4 and should traverse routers if not filtered. The scenario says the service is confirmed running, so the difference is more likely explained by the firewall rule between subnets, not the scan technique itself.

  • ✗

    The -sS scan requires the --send-eth option when crossing subnets, otherwise Nmap uses IP packets that routers cannot forward.

    Why it's wrong here

    The --send-eth option forces Nmap to send packets at the Ethernet layer, which is only useful on the local segment and would actually prevent routing. Nmap normally sends IP packets that routers forward correctly. This option choice is unrelated to the filtering behavior described.

  • ✗

    Nmap SYN scans only work on the local subnet because they require layer-2 adjacency to receive responses.

    Why it's wrong here

    This is a common misconception. SYN scans operate at layer 3 and layer 4 and do not require layer-2 adjacency; they can scan remote hosts across routers as long as the packets are not filtered. The statement is technically false and misrepresents how -sS works.

  • ✓

    A firewall or ACL between the subnets is blocking TCP/445, so the SYN packets never reach the target or the responses never return, resulting in a filtered or no-response state.

    Why this is correct

    When the same service responds locally but not across a router, the most likely explanation is an intermediate firewall or ACL dropping TCP/445. The scan itself is valid; the network path is filtering the probe or its response, which is why the port appears filtered or unreachable from the remote subnet.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.