Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

A penetration tester has been given a target IP address and needs to quickly determine which services are running on the target. Which Nmap option should the tester use to perform a SYN scan with service version detection and default NSE scripts?

⚠ Common exam trap

The trap is that many test-takers select -A (Option C) believing it is the quickest way to meet all requirements. While -A does enable a SYN scan (when run with root privileges), version detection, and default scripts, it also activates OS detection and traceroute, which are not requested and may add unnecessary time and network activity. The question specifically asks for the combination -sS -sV -sC, which achieves only the required functions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

nmap -sS -sV -sC 192.168.1.10

The -sS flag initiates a SYN stealth scan, -sV enables service version detection by probing open ports to determine application and version information, and -sC runs the default set of NSE scripts for common enumeration tasks. Together, these three options fulfill the requirement to quickly identify running services with version details and additional script-based reconnaissance, all while using a half-open TCP scan to minimize log generation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    nmap -sS -sV -sC 192.168.1.10

    Why this is correct

    Correct. SYN scan, version detection, and default scripts.

  • ✗

    nmap -sT -sV -sC 192.168.1.10

    Why it's wrong here

    This uses TCP connect scan, which is slower and more detectable than SYN scan.

  • ✗

    nmap -A 192.168.1.10

    Why it's wrong here

    Aggressive scan includes OS detection, version, scripts, and traceroute, but may be too loud.

  • ✗

    nmap -sS -O 192.168.1.10

    Why it's wrong here

    This scans with OS detection but no version or script scanning.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.