Courseiva

GSEC · domain

Vulnerability Scanning and Penetration Testing

This GSEC domain covers finding and validating weaknesses through vulnerability scanning and penetration testing. Expect questions on authenticated versus unauthenticated scanning, scanner configuration, credential and protocol issues, Nmap scan selection, open-source tooling, and post-exploitation local enumeration to catch gaps remote scans miss.

8 questions2 easy3 medium3 hard

Focused practice

Practice Vulnerability Scanning and Penetration Testing questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Vulnerability Scanning and Penetration Testing

Be able to configure and troubleshoot authenticated scans, pick the right Nmap scan type, and choose an open-source scanner. The key is matching scan method to target: authenticated scans need working credentials and correct protocol settings, while local enumeration catches what remote scans miss.

Configuring authenticated SSH scans on Linux and troubleshooting scanner login failures

Choosing Nmap scan types for authenticated Windows scanning with domain admin rights

Selecting open-source, maintained vulnerability scanners for subnet-wide assessments

Using local enumeration on a compromised host to find missing patches and misconfigurations

Watch out for

Common Vulnerability Scanning and Penetration Testing exam traps

  • ▸Assuming valid credentials guarantee scanner login; SSH key format, sudo restrictions, or shell settings can break authenticated scans.
  • ▸Confusing Nmap service/version detection with authenticated vulnerability scanning; Nmap alone does not log in and audit patches.
  • ▸Trusting a single unauthenticated remote scan as complete, missing local-only patch and configuration issues exposed after a shell.

Question index

All Vulnerability Scanning and Penetration Testing questions (8)

Click any question to see the full explanation, or start a practice session above.

1

During an authorized penetration test, a tester obtains a low-privilege shell on a Windows server and wants to identify missing patches and insecure configurations that a remote unauthenticated scan may have missed. Which action BEST supports this goal?

Medium
2

A penetration tester is planning a web application assessment for a client. The tester wants to combine automated scanning with manual techniques to maximize coverage. Which two actions are MOST appropriate to include in the plan? (Choose two.)

Medium
3

A junior security analyst at a healthcare company must scan a subnet of 254 hosts for known vulnerabilities. The analyst has no budget for commercial tools and needs a scanner that is open source, actively maintained, and capable of authenticated and unauthenticated checks. Which tool BEST meets these requirements?

Easy
4

A security analyst is preparing to run an authenticated vulnerability scan against a Windows Server 2019 host. The analyst has domain credentials with local administrator rights on the target. Which Nmap scan type should the analyst use to perform a full TCP connect scan without requiring raw packet privileges?

Easy
5

A penetration tester is preparing an authorized internal assessment and must decide how to handle the discovery phase before running exploitation attempts. The client's rules of engagement permit scanning but forbid any action that could cause a denial of service on production hosts. The tester's goal is to map live hosts, open ports, and service versions with minimal impact while still gathering enough data to plan later exploitation. Which approach best satisfies both the engagement constraints and the assessment objective?

Medium
6

A security consultant is configuring a Tenable Nessus scan to assess a mixed environment of Windows and Linux servers. The consultant needs to ensure the scan can authenticate to targets and perform local checks without relying on agent installation. Which two Nessus scan settings should the consultant configure to provide credentials for authenticated scanning? (Choose two.)

Hard
7

A security team is configuring an authenticated vulnerability scan of a Linux server farm using SSH. The scanner reports that it cannot log in to several hosts even though the same credentials work manually. Which configuration change is MOST likely to resolve the issue?

Hard
8

A vulnerability scan of a production web server reports a critical remote code execution vulnerability, but the system administrator insists the server is fully patched. The scanner used only unauthenticated checks. Which step should the security analyst take FIRST to resolve the discrepancy?

Hard

Frequently asked questions

What does the Vulnerability Scanning and Penetration Testing domain cover on the GSEC exam?
Be able to configure and troubleshoot authenticated scans, pick the right Nmap scan type, and choose an open-source scanner. The key is matching scan method to target: authenticated scans need working credentials and correct protocol settings, while local enumeration catches what remote scans miss.
How many questions are in this domain?
This page lists all 8 Vulnerability Scanning and Penetration Testing questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Vulnerability Scanning and Penetration Testing questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gsec GIAC-GSEC vulnerability scanning and penetration testing Practice Questions