Courseiva

GSEC · topic practice

Vulnerability Scanning and Penetration Testing practice questions

This GSEC domain covers finding and validating weaknesses through vulnerability scanning and penetration testing. Expect questions on authenticated versus unauthenticated scanning, scanner configuration, credential and protocol issues, Nmap scan selection, open-source tooling, and post-exploitation local enumeration to catch gaps remote scans miss.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
13 questionsDomain: Vulnerability Scanning and Penetration Testing

What the exam tests

What to know about Vulnerability Scanning and Penetration Testing

Be able to configure and troubleshoot authenticated scans, pick the right Nmap scan type, and choose an open-source scanner. The key is matching scan method to target: authenticated scans need working credentials and correct protocol settings, while local enumeration catches what remote scans miss.

Configuring authenticated SSH scans on Linux and troubleshooting scanner login failures

Choosing Nmap scan types for authenticated Windows scanning with domain admin rights

Selecting open-source, maintained vulnerability scanners for subnet-wide assessments

Using local enumeration on a compromised host to find missing patches and misconfigurations

Watch out for

Common Vulnerability Scanning and Penetration Testing exam traps

  • ▸Assuming valid credentials guarantee scanner login; SSH key format, sudo restrictions, or shell settings can break authenticated scans.
  • ▸Confusing Nmap service/version detection with authenticated vulnerability scanning; Nmap alone does not log in and audit patches.
  • ▸Trusting a single unauthenticated remote scan as complete, missing local-only patch and configuration issues exposed after a shell.

Practice set

Vulnerability Scanning and Penetration Testing questions

13 questions · select your answer, then reveal the explanation

A security analyst is preparing to scan a production network segment containing legacy medical devices that cannot be patched or rebooted. The analyst wants to identify exposed services without causing device crashes or service interruptions. Which Nmap scan technique should the analyst use?

A penetration tester is conducting an authorized assessment of a web application. The tester wants to identify vulnerabilities in the application's authentication and session management without causing denial of service or modifying data. Which tool and mode should the tester use to perform a safe, non-destructive scan?

Question 3mediummultiple choice
Review the full subnetting walkthrough →

A penetration tester is conducting an internal assessment and wants to discover live hosts on a subnet without performing port scanning. The tester has administrative privileges on the attacking machine. Which Nmap command should the tester use to perform a ping sweep only?

A security analyst is reviewing a vulnerability scan report and notices a finding for CVE-2021-44228 (Log4Shell) on a server. The analyst needs to confirm whether the vulnerability is actually exploitable. Which Metasploit module should the analyst use to safely verify the presence of the Log4Shell vulnerability without executing a full remote code payload?

A penetration tester is using OpenVAS (Greenbone Vulnerability Management) to scan a client network. The tester wants to ensure the scan does not disrupt fragile legacy systems that may crash under heavy load. Which OpenVAS scan configuration setting should the tester adjust to limit the number of concurrent hosts and checks?

A security analyst is preparing to run an authenticated vulnerability scan against a Windows Server 2019 host. The analyst has domain credentials with local administrator rights on the target. Which Nmap scan type should the analyst use to perform a full TCP connect scan without requiring raw packet privileges?

Question 7easymultiple choice
Review the full subnetting walkthrough →

A junior security analyst at a healthcare company must scan a subnet of 254 hosts for known vulnerabilities. The analyst has no budget for commercial tools and needs a scanner that is open source, actively maintained, and capable of authenticated and unauthenticated checks. Which tool BEST meets these requirements?

During an authorized penetration test, a tester obtains a low-privilege shell on a Windows server and wants to identify missing patches and insecure configurations that a remote unauthenticated scan may have missed. Which action BEST supports this goal?

A security consultant is configuring a Tenable Nessus scan to assess a mixed environment of Windows and Linux servers. The consultant needs to ensure the scan can authenticate to targets and perform local checks without relying on agent installation. Which two Nessus scan settings should the consultant configure to provide credentials for authenticated scanning? (Choose two.)

A security team is configuring an authenticated vulnerability scan of a Linux server farm using SSH. The scanner reports that it cannot log in to several hosts even though the same credentials work manually. Which configuration change is MOST likely to resolve the issue?

A penetration tester is planning a web application assessment for a client. The tester wants to combine automated scanning with manual techniques to maximize coverage. Which two actions are MOST appropriate to include in the plan? (Choose two.)

A vulnerability scan of a production web server reports a critical remote code execution vulnerability, but the system administrator insists the server is fully patched. The scanner used only unauthenticated checks. Which step should the security analyst take FIRST to resolve the discrepancy?

A penetration tester is preparing an authorized internal assessment and must decide how to handle the discovery phase before running exploitation attempts. The client's rules of engagement permit scanning but forbid any action that could cause a denial of service on production hosts. The tester's goal is to map live hosts, open ports, and service versions with minimal impact while still gathering enough data to plan later exploitation. Which approach best satisfies both the engagement constraints and the assessment objective?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Vulnerability Scanning and Penetration Testing sessions

Start a Vulnerability Scanning and Penetration Testing only practice session

Every question in these sessions is drawn from the Vulnerability Scanning and Penetration Testing domain — nothing else.

Related practice questions

Related GSEC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GSEC exam test about Vulnerability Scanning and Penetration Testing?
Be able to configure and troubleshoot authenticated scans, pick the right Nmap scan type, and choose an open-source scanner. The key is matching scan method to target: authenticated scans need working credentials and correct protocol settings, while local enumeration catches what remote scans miss.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Vulnerability Scanning and Penetration Testing questions in a focused session?
Yes — the session launcher on this page draws every question from the Vulnerability Scanning and Penetration Testing domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GSEC topics?
Use the topic links above to move to related areas, or go back to the GSEC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GSEC exam covers. They are not copied from any real exam or dump site.