easyMultiple Choice
PT0-002 Practice Question: A penetration tester is analyzing a Python script…
A penetration tester is analyzing a Python script that uses the 'socket' module to create a TCP connection to a target IP and port. The script then sends a payload (e.g., 'GET / HTTP/1.0\r\n\r\n') and waits for a response. Which tool function is this script most likely performing?
⚠ Common exam trap
Test-takers frequently confuse banner grabbing with port scanning because both involve connecting to a port, but banner grabbing focuses on service identification from a single connection, not enumeration of open ports.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Banner grabbing
The script creates a TCP connection, sends an HTTP GET request, and waits for a response. This is the classic behavior of banner grabbing, where the goal is to retrieve the service banner (e.g., HTTP server version) from the target. The 'socket' module is used to manually craft the connection and payload, which is a low-level technique for service identification, not for scanning multiple ports or assessing vulnerabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Port scanning
Why it's wrong here
Port scanning involves systematically probing multiple TCP or UDP ports to enumerate open services, often using SYN, connect, or ACK techniques. This script targets a single fixed port and sends an application-layer HTTP payload, then reads one response; it does not iterate across a range of ports or classify port states. Thus it cannot be considered port scanning, because the goal and mechanism are service identification, not port discovery.
- ✓
Banner grabbing
Why this is correct
Banner grabbing is the active retrieval of a service's identity by sending a connection or request and observing the returned greeting or header, such as an HTTP Server header. In this script, sending a crafted payload and reading the subsequent response is precisely the mechanism used to capture the service banner, which reveals the software and version. This is a foundational reconnaissance step for later vulnerability research, but the single request-response exchange itself performs banner grabbing.
- ✗
Vulnerability scanning
Why it's wrong here
A TCP connection sending a single HTTP request and awaiting a response performs a basic banner grab or service identification, not vulnerability scanning, which requires a database of known weaknesses and conditional logic to test for specific misconfigurations or missing patches. This option is tempting because sending crafted payloads to elicit responses is a preliminary step in vulnerability assessment, and in a scenario where the script iterated through multiple exploit checks against the response, it would constitute a vulnerability scanner.
- ✗
Password cracking
Why it's wrong here
Password cracking requires repeated authentication attempts, such as submitting username/password pairs, or offline operations like hash comparison and dictionary or brute-force attacks. The described script makes a single TCP connection, sends a service request, and reads the response; it does not submit credentials, handle authentication challenges, or evaluate a success/failure decision. The response is an application banner, not an authentication result, so this is not password cracking.
Visual reference
Go deeper
Related to this question
Learn chapter
Red Team Exercises vs Penetration Tests
Key term
Banner grabbing
Banner grabbing is the process of connecting to a remote service to capture the banner it sends, which often reveals software type and version for reconnaissance.
Key term
Payload
In IT and cybersecurity, a payload is the core data or malicious code delivered within a packet, file, or attack that performs the actual intended action.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.