
GIAC Penetration Tester (GPEN)
Domain 1Objective 3
Scanning and Host Discovery GPEN Practice Questions (Page 6)
Part of the Penetration Testing Foundations domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 4–7 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
7concepts
Questions 26–30
- 26
A tester has discovered an open port 3306 on a target. The tester wants to determine the exact version of the MySQL database running on that port. Which Nmap command should be used?
Select an answer first - 27
What is the primary purpose of operating system fingerprinting?
Select an answer first - 28
A tester is performing a port scan against a target and wants to hide the source IP address by making it appear that the scan is coming from multiple different hosts. Which Nmap option should be used?
Select an answer first - 29
A tester has identified an open port 25 on a target and wants to determine the exact version of the mail server software. The tester runs 'nmap -sV -p 25 192.168.1.10' but the output only shows '25/tcp open smtp' without a version. Which of the following is the most likely reason for this?
Select an answer first - 30
A penetration tester has run an Nmap scan and received the following output for a target host: PORT STATE SERVICE 22/tcp open ssh 80/tcp open http 443/tcp open https 3306/tcp filtered mysql Which interpretation is correct?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.