GSEC Practice Question: Vulnerability Scanning and Penetration Testing
A security team is configuring an authenticated vulnerability scan of a Linux server farm using SSH. The scanner reports that it cannot log in to several hosts even though the same credentials work manually. Which configuration change is MOST likely to resolve the issue?
⚠ Common exam trap
The trap here is assuming that because manual SSH with a password works, the scanner must also use passwords, when in fact the scanner may be configured for key-based authentication that has not been provisioned.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Allow the scanner's public key in the authorized_keys file for the scan account
Authenticated SSH scans rely on the scanner presenting a key that the target accepts. When manual logins work but the scanner fails, the usual cause is that the scanner's public key has not been installed in the scan account's authorized_keys file. Adding that key restores authentication without weakening the host's security posture, unlike enabling password authentication or disabling SELinux.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Allow the scanner's public key in the authorized_keys file for the scan account
Why this is correct
Authenticated SSH scans typically use a key pair generated by the scanner. If the scanner's public key is not present in the target account's authorized_keys file, the scanner cannot authenticate even when manual password logins succeed. Adding the scanner's public key to the authorized_keys file for the scan account directly resolves this failure.
- ✗
Enable password authentication on the target hosts
Why it's wrong here
Enabling password authentication would allow the scanner to use passwords, but the scenario does not state that passwords are the intended method. Many hardened environments deliberately disable password authentication in favor of keys. Turning it on weakens security and may not address the actual problem if the scanner is configured for key-based access.
- ✗
Change the SSH port on the targets to 2222
Why it's wrong here
Changing the SSH port would only matter if the scanner were configured to use a non-default port and the targets were listening elsewhere. The scenario gives no indication of a port mismatch, and manual SSH logins work on the default port. Altering the port adds complexity without addressing the authentication failure.
- ✗
Disable SELinux on the target hosts
Why it's wrong here
SELinux enforces mandatory access controls and could block unusual login contexts, but it would typically also affect manual SSH sessions. Since manual logins succeed, SELinux is not the cause. Disabling it reduces the security posture and does not resolve the scanner-specific authentication problem.
Visual reference
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.