easyMultiple Choice
PT0-002 Practice Question: A penetration tester is analyzing a Bash script…
A penetration tester is analyzing a Bash script that contains the following line: 'for ip in $(cat ip_list.txt); do nc -zv $ip 22; done'. What is the primary purpose of this script?
⚠ Common exam trap
Test-takers frequently confuse `-z` (zero I/O scan) with banner grabbing or interactive shell access, assuming netcat always reads banners or spawns shells, when in fact `-z` explicitly prevents data transfer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To test if port 22 is open on each IP in the list
The script uses `nc -zv $ip 22` which performs a TCP connection test to port 22 on each IP from the list. The `-z` flag tells netcat to scan without sending any data, and `-v` enables verbose output, so it only reports whether the connection succeeded (port open) or failed (port closed or filtered). This is a classic port connectivity check, not a full banner grab or shell establishment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To perform a banner grab on port 22 for each IP
Why it's wrong here
With the -z flag, netcat exits immediately after the TCP handshake and does not read any data from the remote service. Banner grabbing relies on reading the initial service banner that is sent after connecting, which requires a full connection with data transfer rather than a zero-I/O scan. Thus this script is not performing banner grabbing; it is only checking reachability of port 22.
- ✓
To test if port 22 is open on each IP in the list
Why this is correct
The -z flag instructs netcat to scan for open ports by completing a TCP handshake and then closing the connection without transmitting payload data. If the handshake succeeds, the port is reported as open; otherwise it is reported as closed or filtered. Therefore the script checks whether each IP has port 22 open, which is a simple port availability test.
- ✗
To establish a remote shell connection to each IP on port 22
Why it's wrong here
A remote shell requires bidirectional data exchange over the established TCP connection, typically using options like -e (execute) or a reverse shell payload. The -z flag deliberately suppresses all data send/receive, causing the connection to close right after the handshake. Consequently, this command cannot spawn or interact with a shell on any of the target IPs on port 22.
- ✗
To scan all 65535 ports on each IP in the list
Why it's wrong here
The command explicitly designates port 22 as the destination port, which means netcat will test only that port against each IP address. Scanning all 65535 TCP ports would require a port range or a loop that iterates through every port number, such as 'nc -z target 1-65535'. Since the script fixes port 22, it cannot be a full port scan.
Visual reference
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.