PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is conducting a vulnerability scan of a Linux server using OpenVAS. Which TWO scan configurations would provide the MOST comprehensive results? (Select TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Scan using the 'Full and fast' configuration
Authenticated scans with credentials allow the scanner to log in and check for missing patches, misconfigurations, and vulnerabilities that are not visible externally. Full and fast scan configurations are typical for comprehensive coverage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Scan using the 'Full and fast' configuration
Why this is correct
The 'Full and fast' profile in Nessus is the recommended comprehensive scan policy: it activates all plugins except those tagged as 'Denial of Service' or potentially disruptive, and it enables safe port scanning techniques. This ensures maximum vulnerability coverage across all plugin families (such as Windows, Linux, web applications, and databases) while still avoiding outright service disruption. It is the default starting point for a penetration test's vulnerability assessment phase.
- ✗
Scan using only the 'Discovery' category
Why it's wrong here
Restricting the scan to the 'Discovery' plugin family only performs host enumeration, port scanning, and service version detection—it never executes a single vulnerability check. This makes it useful for creating an asset inventory or attack surface map, but it cannot identify missing patches, weak configurations, or exploitable flaws. As a result, it fails the core objective of a vulnerability scan, which is to detect known and potentially exploitable weaknesses.
- ✓
Authenticated scan with SSH credentials
Why this is correct
An authenticated SSH scan provides privileged-level insight: after login, the scanner can query package managers, inspect configuration files, and enumerate installed software versions to precisely map missing patches and insecure settings. This dramatically reduces false positives because the scanner sees the actual system state rather than guessing from banner versions, and it also unlocks local-only vulnerability checks (e.g., privilege escalation issues) that are invisible to unauthenticated scanners. It is a best practice for any environment where credentials can be safely provided.
- ✗
Scan using the 'Denial of Service' configuration
Why it's wrong here
The 'Denial of Service' configuration is a specialized scan policy that executes plugins designed to stress or crash services—for example, by sending malformed packets, exhausting connection tables, or triggering resource exhaustion. Running this profile against production systems can cause outages, violate the terms of an authorization, and is rarely part of standard vulnerability scanning unless the client explicitly requests resilience testing. Therefore, it is an inappropriate choice for a routine penetration test assessment.
- ✗
Unauthenticated scan with default settings
Why it's wrong here
An unauthenticated scan with default settings runs without any credentials, so it can only fingerprint services from network banners and perform remote checks; it will entirely miss vulnerabilities that require authenticated access, such as missing patches that are only visible via the local package manager. While this approach is safe and easy, it generates a higher rate of false positives (because banner versions can be inaccurate) and false negatives, making it far less comprehensive than a Full and fast or credentialed scan. It is acceptable for an initial external reconnaissance pass, but not as the primary vulnerability scan.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.