PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is conducting active reconnaissance and wants to perform a SYN scan on a target network. During the scan, the tester notices that some ports are reported as filtered. What does a filtered port status typically indicate in Nmap?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A firewall is blocking the probe packets.
Filtered ports in Nmap indicate that a firewall, packet filter, or other network obstacle is blocking the probe packets, preventing Nmap from determining whether the port is open or closed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The port is closed and the target responded with a RST packet.
Why it's wrong here
When Nmap sends a SYN probe to a closed port, the TCP stack responds with an RST packet, which Nmap interprets as a definitive 'closed' state. This is an unambiguous response that indicates the port is reachable but not accepting connections. Because the RST provides a clear signal, Nmap would never label the port as 'filtered', which specifically implies an absence of response or an ICMP unreachable message.
- ✗
The port is open but no service is listening.
Why it's wrong here
An open port with no service listening would still complete the TCP handshake (or at least respond with SYN/ACK to the SYN probe), because the kernel accepts the connection even if no application is bound, pending a connection queue. Nmap would classify that port as 'open' and then possibly note that no service was detected during version detection. 'Filtered' indicates that the probe was dropped or blocked by a firewall, so the scanner cannot see any TCP-level response, which is fundamentally different from a port that responds at the kernel level.
- ✗
The target is not responding to any probes.
Why it's wrong here
If the target is not responding to any probes, the issue is likely host-level: the host might be down, or the network path is broken, or Nmap may treat all ports as 'filtered' only if the host is confirmed up but drops all packets. However, 'filtered' per-port specifically indicates that a firewall is interfering with the probe to that port, typically by dropping the packet without any response. In this scenario, the target as a whole may be unresponsive, but that is not the same as a single port being filtered due to restrictive firewall rules.
- ✓
A firewall is blocking the probe packets.
Why this is correct
When Nmap receives no response (or an ICMP unreachable message, such as type 3 code 13, administratively prohibited) to a SYN probe to a specific port, it labels that port 'filtered'. This indicates that a firewall or packet-filtering device is interfering with the probe, either by dropping the packet silently or by sending back a rejection message. Consequently, Nmap cannot definitively determine whether the port is open or closed because it lacks a TCP-level response like SYN/ACK or RST. This is a common result when stateful firewalls inspect and block unsolicited inbound packets during active reconnaissance.
Visual reference
Go deeper
Related to this question
Learn chapter
Masscan and ZMap for Fast Port Scanning
Key term
Nmap
Nmap is a network scanning tool used to discover hosts, services, and operating systems on a computer network.
Key term
Active reconnaissance
Active reconnaissance is the process of directly interacting with a target system or network to gather information, often through scanning and probing.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.