Courseiva
easyMultiple Choice

PT0-002 Practice Question: A penetration tester is analyzing a Bash script…

A penetration tester is analyzing a Bash script that contains the following line: 'for ip in $(cat ip_list.txt); do nc -zv $ip 22; done'. What is the primary purpose of this script?

⚠ Common exam trap

Test-takers frequently confuse `-z` (zero I/O scan) with banner grabbing or interactive shell access, assuming netcat always reads banners or spawns shells, when in fact `-z` explicitly prevents data transfer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To test if port 22 is open on each IP in the list

The script uses `nc -zv $ip 22` which performs a TCP connection test to port 22 on each IP from the list. The `-z` flag tells netcat to scan without sending any data, and `-v` enables verbose output, so it only reports whether the connection succeeded (port open) or failed (port closed or filtered). This is a classic port connectivity check, not a full banner grab or shell establishment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To perform a banner grab on port 22 for each IP

    Why it's wrong here

    With the -z flag, netcat exits immediately after the TCP handshake and does not read any data from the remote service. Banner grabbing relies on reading the initial service banner that is sent after connecting, which requires a full connection with data transfer rather than a zero-I/O scan. Thus this script is not performing banner grabbing; it is only checking reachability of port 22.

  • ✓

    To test if port 22 is open on each IP in the list

    Why this is correct

    The -z flag instructs netcat to scan for open ports by completing a TCP handshake and then closing the connection without transmitting payload data. If the handshake succeeds, the port is reported as open; otherwise it is reported as closed or filtered. Therefore the script checks whether each IP has port 22 open, which is a simple port availability test.

  • ✗

    To establish a remote shell connection to each IP on port 22

    Why it's wrong here

    A remote shell requires bidirectional data exchange over the established TCP connection, typically using options like -e (execute) or a reverse shell payload. The -z flag deliberately suppresses all data send/receive, causing the connection to close right after the handshake. Consequently, this command cannot spawn or interact with a shell on any of the target IPs on port 22.

  • ✗

    To scan all 65535 ports on each IP in the list

    Why it's wrong here

    The command explicitly designates port 22 as the destination port, which means netcat will test only that port against each IP address. Scanning all 65535 TCP ports would require a port range or a loop that iterates through every port number, such as 'nc -z target 1-65535'. Since the script fixes port 22, it cannot be a full port scan.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.