Courseiva

GSEC Practice Question: Vulnerability Scanning and Penetration Testing

A penetration tester is planning a web application assessment for a client. The tester wants to combine automated scanning with manual techniques to maximize coverage. Which two actions are MOST appropriate to include in the plan? (Choose two.)

⚠ Common exam trap

The trap here is treating automated scanning as sufficient on its own, or including high-risk actions like denial-of-service testing that fall outside a typical web application assessment scope.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Perform manual testing of authentication and session management flows

A thorough web application assessment pairs automated scanning with manual techniques. Automated tools like OWASP ZAP provide broad coverage of common vulnerabilities, while manual testing of authentication and session management uncovers logic and access control flaws that scanners cannot reliably detect. The other options either address infrastructure rather than the application or introduce unnecessary risk without improving coverage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Launch a denial-of-service test against the production application to check resilience

    Why it's wrong here

    Denial-of-service testing against a production application can cause outages and is rarely authorized in a standard web assessment. It does not help find application vulnerabilities and introduces significant risk. Unless explicitly scoped, this action is inappropriate and could violate the rules of engagement, so it should not be included.

  • ✗

    Use a network protocol analyzer to capture all traffic between the tester and the application

    Why it's wrong here

    Capturing traffic can help confirm cleartext transmission or inspect tokens, but it is not a primary web application assessment technique and does not systematically find injection or logic flaws. It may also capture sensitive data that must be handled carefully. As a standalone inclusion it adds limited value compared with automated scanning and manual testing.

  • ✓

    Perform manual testing of authentication and session management flows

    Why this is correct

    Manual testing is essential for logic flaws, broken authentication, and session management issues that automated scanners often miss. By exercising login, logout, password reset, and session fixation scenarios by hand, the tester uncovers vulnerabilities that require contextual understanding, which complements the automated scan and increases overall assessment quality.

  • ✓

    Run an automated web vulnerability scanner such as OWASP ZAP against the application

    Why this is correct

    OWASP ZAP is an open-source web application scanner that can crawl the application and detect common issues like SQL injection, cross-site scripting, and misconfigurations. Including it provides broad, repeatable coverage and a baseline of findings that manual testing can then validate and expand upon, making it an appropriate part of a combined approach.

  • ✗

    Run a full TCP port scan of the web server before testing the application

    Why it's wrong here

    A port scan identifies open services on the host but does not assess the web application itself. While useful for infrastructure context, it does not contribute to finding application-layer vulnerabilities such as SQL injection or broken access control. The scenario focuses on web application assessment, so this is not a primary action.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.