Courseiva

GSEC Practice Question: Vulnerability Scanning and Penetration Testing

A penetration tester is preparing an authorized internal assessment and must decide how to handle the discovery phase before running exploitation attempts. The client's rules of engagement permit scanning but forbid any action that could cause a denial of service on production hosts. The tester's goal is to map live hosts, open ports, and service versions with minimal impact while still gathering enough data to plan later exploitation. Which approach best satisfies both the engagement constraints and the assessment objective?

⚠ Common exam trap

The trap here is assuming that a faster or broader scan always produces better assessment data, when in a production environment the engagement's safety constraints make scan pacing and scope the deciding factors.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Perform a phased Nmap discovery using host discovery first, then targeted service/version detection with conservative timing options such as -T2 and limited port ranges, documenting results before any exploitation phase.

The phased approach with host discovery followed by conservative service/version detection controls packet volume and timing, which is what keeps a scan from disrupting production services. Narrowing targets before enumeration also makes later exploitation planning more accurate. Aggressive timing, immediate exploitation, or relying on stale inventory all conflict with either the safety constraint or the objective of verifying live services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Perform a phased Nmap discovery using host discovery first, then targeted service/version detection with conservative timing options such as -T2 and limited port ranges, documenting results before any exploitation phase.

    Why this is correct

    A phased approach separates live-host discovery from service enumeration, letting the tester narrow the target set and apply conservative timing and port scope. Version detection with controlled timing reduces the chance of overwhelming fragile services, directly honoring the no-denial-of-service constraint. Documenting results before exploitation supports repeatable planning and keeps later phases tied to validated findings rather than assumptions.

  • ✗

    Skip active scanning entirely and rely only on the client's existing asset inventory spreadsheet, then begin exploitation attempts against the listed hosts.

    Why it's wrong here

    Relying solely on an inventory spreadsheet abandons the tester's responsibility to verify what is actually reachable and listening, so stale or incomplete records would skew the assessment. It also ignores the engagement objective of mapping live hosts, ports, and versions. Beginning exploitation against unverified inventory entries could target decommissioned or unauthorized systems, creating legal and safety problems.

  • ✗

    Run a full Nmap scan with -sS and no timing adjustments across the entire /16, then immediately launch the exploitation framework against every discovered service.

    Why it's wrong here

    A SYN scan across a /16 without timing controls can generate a large volume of packets and saturate network links or overwhelm legacy devices, which risks the denial-of-service condition the rules of engagement prohibit. Coupling discovery directly to exploitation also ignores the discipline of validating findings before attempting exploitation, and it can destabilize production services. This approach prioritizes speed over the client's stated safety constraints.

  • ✗

    Use a single aggressive Nmap scan with -T5 and the default top-1000 ports, then treat every open port as an exploitable finding in the final report.

    Why it's wrong here

    The -T5 timing template sends packets as fast as possible, which is exactly the behavior most likely to cause service degradation or packet loss on production systems, violating the engagement constraint. Treating every open port as an exploitable vulnerability also produces false positives and misrepresents risk in the report. Discovery data alone does not establish exploitability without validation.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.