hardMultiple Choice
PT0-002 Practice Question: A penetration tester is performing a…
A penetration tester is performing a vulnerability scan on a web server that uses HTTPS. The tester wants to identify the server's SSL/TLS configuration weaknesses without overwhelming the server. Which Nmap command is most appropriate?
⚠ Common exam trap
Test-takers frequently choose `-sC` (default scripts) thinking it covers SSL checks, but it does not run the dedicated cipher enumeration script, which is the only option that specifically and safely identifies SSL/TLS weaknesses without aggressive scanning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
nmap -sV --script ssl-enum-ciphers -p 443 target
The `ssl-enum-ciphers` NSE script enumerates all supported SSL/TLS ciphers and protocols on the target, providing a detailed assessment of cryptographic weaknesses (e.g., weak ciphers, outdated TLS versions). The `-sV` flag enables version detection, and `-p 443` targets the HTTPS port, while the script itself is designed to be lightweight and not overwhelm the server, making it ideal for a non-intrusive vulnerability scan.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
nmap -sV --script ssl-enum-ciphers -p 443 target
Why this is correct
This command is correct because -sV triggers version detection, and --script ssl-enum-ciphers explicitly invokes the Nmap script that enumerates SSL/TLS ciphers, protocols, and known weaknesses such as BEAST, POODLE, or weak key exchange. The script sends probe connections to the HTTPS service on port 443 and reports the strength of each cipher, which is precisely what a vulnerability scan of a web service requires. Restricting the scan to -p 443 focuses it on the SSL/TLS endpoint without extraneous traffic.
- ✗
nmap -sT -A -T4 -p 443 target
Why it's wrong here
The -sT flag performs a full TCP connect handshake, and -A turns on OS detection, version detection, default script scanning, and traceroute, but it does not specifically run the ssl-enum-ciphers script. While -A may detect the service version and run some SSL-related default scripts like ssl-cert, it will not produce a comprehensive cipher enumeration with strength ratings. The -T4 timing template only increases scan speed and does not alter script selection, so this command answers a different question: what is running on port 443, not how secure its ciphers are.
- ✗
nmap -sU -p 443 target
Why it's wrong here
Using -sU directs Nmap to perform a UDP scan, but HTTPS on port 443 is a TCP-based service; UDP 443 is typically used by QUIC/HTTP/3, not traditional HTTPS. A UDP scan will send minimal probes and is unlikely to elicit a meaningful response from a TCP-only HTTPS server, let alone enumerate its cipher suites. Finally, no script is specified, so even on a UDP response there would be no cipher analysis, making this command fundamentally unsuited for the stated vulnerability scan.
- ✗
nmap -sC -p 443 target
Why it's wrong here
The -sC option executes the default script category, which includes safe scripts such as ssl-cert and ssl-date, but it deliberately excludes the ssl-enum-ciphers script because that script is not in the default set. Without explicitly using --script ssl-enum-ciphers, the scan will only retrieve the certificate expiration and basic SSL information, not test each cipher for weaknesses. Therefore, this command falls short of the required cipher enumeration and would leave the tester with an incomplete vulnerability assessment.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.