PT0-002 Vulnerability Discovery and Analysis Practice Question
A penetration tester has been given a target IP address and needs to quickly determine which services are running on the target. Which Nmap option should the tester use to perform a SYN scan with service version detection and default NSE scripts?
⚠ Common exam trap
The trap is that many test-takers select -A (Option C) believing it is the quickest way to meet all requirements. While -A does enable a SYN scan (when run with root privileges), version detection, and default scripts, it also activates OS detection and traceroute, which are not requested and may add unnecessary time and network activity. The question specifically asks for the combination -sS -sV -sC, which achieves only the required functions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
nmap -sS -sV -sC 192.168.1.10
The -sS flag initiates a SYN stealth scan, -sV enables service version detection by probing open ports to determine application and version information, and -sC runs the default set of NSE scripts for common enumeration tasks. Together, these three options fulfill the requirement to quickly identify running services with version details and additional script-based reconnaissance, all while using a half-open TCP scan to minimize log generation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
nmap -sS -sV -sC 192.168.1.10
Why this is correct
Correct. SYN scan, version detection, and default scripts.
- ✗
nmap -sT -sV -sC 192.168.1.10
Why it's wrong here
This uses TCP connect scan, which is slower and more detectable than SYN scan.
- ✗
nmap -A 192.168.1.10
Why it's wrong here
Aggressive scan includes OS detection, version, scripts, and traceroute, but may be too loud.
- ✗
nmap -sS -O 192.168.1.10
Why it's wrong here
This scans with OS detection but no version or script scanning.
Go deeper
Related to this question
Learn chapter
Nmap Scanning Techniques
Key term
Enumeration
Enumeration is the systematic process of extracting detailed information about a target system, such as user accounts, network shares, services, and configurations, used during the reconnaissance phase of a security assessment.
Key term
Nmap
Nmap is a network scanning tool used to discover hosts, services, and operating systems on a computer network.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.