
GIAC Penetration Tester (GPEN)
Domain 1Objective 3
Scanning and Host Discovery GPEN Practice Questions (Page 1)
Part of the Penetration Testing Foundations domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 4–7 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
7concepts
Questions 1–5
- 1
During an internal penetration test, a tester needs to identify open TCP ports on a critical server. The client has asked the tester to minimize the chance of the scan being logged by the host's application-level firewall. The tester has root privileges on the scanning machine. Which scan type should the tester use?
Select an answer first - 2
A penetration tester is performing OS fingerprinting on a target and receives a response that suggests the target is running a Linux distribution. The tester wants to confirm the OS guess with additional probes. Which Nmap option should the tester use to increase the accuracy of OS detection?
Select an answer first - 3
A penetration tester has discovered an open port on a web server and needs to determine the exact version of the service to check for known vulnerabilities. The tester wants to avoid crashing the service and wants a reliable version identification. Which Nmap command should the tester use?
Select an answer first - 4
A penetration tester is performing an internal scan of a critical server. The server's host-based firewall is configured to log all established TCP connections, but it does not log incomplete handshakes. The tester needs to identify open TCP ports, but the client has asked the tester to avoid generating logs on the target. Which scan type should the tester use, and why?
Select an answer first - 5
A tester is performing a port scan on a target and wants to avoid detection by a firewall that is configured to drop packets with the SYN flag set. The tester still needs to identify open TCP ports. Which scan type is most likely to succeed?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.