Courseiva

GPEN Scanning and Host Discovery Practice Question

You are scanning a target that resides behind a firewall configured to drop TCP packets with the ACK flag set. You want to determine whether the firewall is stateful or stateless. Which Nmap scan type should you use to help make this determination by analyzing the responses to ACK packets?

⚠ Common exam trap

Watch out — candidates often confuse ACK scan with other scan types that also manipulate TCP flags, such as FIN or NULL scans, which serve different purposes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

TCP ACK scan (-sA)

The TCP ACK scan is specifically designed to map firewall rulesets and determine if they are stateful. By sending ACK packets, it elicits different responses from stateful versus stateless firewalls. Stateful firewalls drop unsolicited ACKs, while stateless firewalls may allow them, causing the host to respond with RST. This differential response is the key to the determination.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    UDP scan (-sU)

    Why it's wrong here

    UDP scanning sends UDP packets to target ports and interprets ICMP port unreachable messages or lack thereof. It is unrelated to TCP ACK behavior and cannot be used to assess firewall statefulness. Since the question focuses on TCP ACK handling, this scan type is irrelevant and would not provide the needed information.

  • ✗

    TCP FIN scan (-sF)

    Why it's wrong here

    A TCP FIN scan sends packets with only the FIN flag set. It is used to bypass some stateless firewalls and identify open ports on systems that follow RFC 793, but it does not help determine if a firewall is stateful. The responses to FIN packets do not reveal how the firewall handles ACK packets, so it is not suitable here.

  • ✓

    TCP ACK scan (-sA)

    Why this is correct

    The TCP ACK scan sends ACK packets to target ports. A stateful firewall will typically drop unsolicited ACKs, resulting in a 'filtered' state, while a stateless firewall may allow them and the host will respond with RST, showing 'unfiltered'. By analyzing whether ports are filtered or unfiltered, you can infer the firewall's nature, making this the correct choice.

  • ✗

    TCP connect scan (-sT)

    Why it's wrong here

    A TCP connect scan completes the full three-way handshake, so it does not rely on ACK packets alone. It is used when raw packet privileges are unavailable and is easily logged by the target. It cannot distinguish between stateful and stateless firewalls because it only shows whether a connection succeeds, not how the firewall treats unsolicited ACKs.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.