GSEC Practice Question: Vulnerability Scanning and Penetration Testing
A penetration tester is planning a web application assessment for a client. The tester wants to combine automated scanning with manual techniques to maximize coverage. Which two actions are MOST appropriate to include in the plan? (Choose two.)
⚠ Common exam trap
The trap here is treating automated scanning as sufficient on its own, or including high-risk actions like denial-of-service testing that fall outside a typical web application assessment scope.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform manual testing of authentication and session management flows
A thorough web application assessment pairs automated scanning with manual techniques. Automated tools like OWASP ZAP provide broad coverage of common vulnerabilities, while manual testing of authentication and session management uncovers logic and access control flaws that scanners cannot reliably detect. The other options either address infrastructure rather than the application or introduce unnecessary risk without improving coverage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Launch a denial-of-service test against the production application to check resilience
Why it's wrong here
Denial-of-service testing against a production application can cause outages and is rarely authorized in a standard web assessment. It does not help find application vulnerabilities and introduces significant risk. Unless explicitly scoped, this action is inappropriate and could violate the rules of engagement, so it should not be included.
- ✗
Use a network protocol analyzer to capture all traffic between the tester and the application
Why it's wrong here
Capturing traffic can help confirm cleartext transmission or inspect tokens, but it is not a primary web application assessment technique and does not systematically find injection or logic flaws. It may also capture sensitive data that must be handled carefully. As a standalone inclusion it adds limited value compared with automated scanning and manual testing.
- ✓
Perform manual testing of authentication and session management flows
Why this is correct
Manual testing is essential for logic flaws, broken authentication, and session management issues that automated scanners often miss. By exercising login, logout, password reset, and session fixation scenarios by hand, the tester uncovers vulnerabilities that require contextual understanding, which complements the automated scan and increases overall assessment quality.
- ✓
Run an automated web vulnerability scanner such as OWASP ZAP against the application
Why this is correct
OWASP ZAP is an open-source web application scanner that can crawl the application and detect common issues like SQL injection, cross-site scripting, and misconfigurations. Including it provides broad, repeatable coverage and a baseline of findings that manual testing can then validate and expand upon, making it an appropriate part of a combined approach.
- ✗
Run a full TCP port scan of the web server before testing the application
Why it's wrong here
A port scan identifies open services on the host but does not assess the web application itself. While useful for infrastructure context, it does not contribute to finding application-layer vulnerabilities such as SQL injection or broken access control. The scenario focuses on web application assessment, so this is not a primary action.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.