
GIAC Penetration Tester (GPEN)
Domain 1Objective 3
Scanning and Host Discovery GPEN Practice Questions (Page 5)
Part of the Penetration Testing Foundations domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 4–7 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
7concepts
Questions 21–25
- 21
Which type of OS fingerprinting analyzes the TCP/IP stack behavior of a target by sending specially crafted packets?
Select an answer first - 22
A penetration tester is scanning a target and wants to evade detection by an IDS that is configured to alert on scans originating from a single IP address. The tester wants to make the scan appear to come from multiple sources. Which Nmap option should the tester use?
Select an answer first - 23
A penetration tester is scanning a target and needs to identify open UDP ports. The tester is aware that UDP scans can be slow and unreliable. Which Nmap command is most appropriate for this task?
Select an answer first - 24
What is the primary purpose of service version detection during a port scan?
Select an answer first - 25
A penetration tester is conducting an external assessment and needs to scan a large range of IP addresses. The tester wants to identify live hosts and open ports efficiently, but the client's firewall is known to drop ICMP packets. Which Nmap command should the tester use to achieve both host discovery and port scanning in one pass?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.