mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is performing an internal…
A penetration tester is performing an internal network assessment and needs to quickly identify all live hosts and their open ports across a large subnet (10.0.0.0/16). The tester wants to minimize network disruption and avoid IDS detection. Which tool and technique should the tester use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a combination of ping sweep with fping followed by nmap -sS (SYN scan) on discovered hosts
Option C is correct because combining fping for a fast ICMP ping sweep to identify live hosts with nmap -sS (a half-open SYN scan) on only those hosts is both efficient and stealthy: the SYN scan never completes the TCP handshake, reducing logging on target services and making IDS detection less likely, while scanning only live hosts minimizes traffic across the 10.0.0.0/16 range. Option A is wrong because -sT completes full TCP connections, which is slower, noisier, and more likely to be logged by target applications. Option B is wrong because masscan at --rate=100 across all ports on all IPs still generates heavy traffic and masscan's characteristic scan patterns are easily flagged by IDS. Option D is wrong because netcat sequential scanning is extremely slow and impractical for a /16 subnet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use nmap with -sT (TCP connect scan) and -p- (all ports) on the entire subnet
Why it's wrong here
A full TCP connect scan completes the three-way handshake on every port, generating heavy connection logging and completing connections that IDS signatures flag. It is tempting because -sT needs no raw-socket privileges, and would suit a small authorised scope where stealth is irrelevant.
- ✗
Use masscan with a low rate (--rate=100) to scan all ports on all IPs
Why it's wrong here
Masscan's asynchronous stateless design still fires packets at every port across 65,536 addresses, and its distinctive probe pattern is readily fingerprinted by IDS. It is tempting because masscan is built for internet-scale speed, and would be correct when raw throughput across huge ranges matters more than concealment.
- ✓
Use a combination of ping sweep with fping followed by nmap -sS (SYN scan) on discovered hosts
Why this is correct
fping sweeps the /16 quickly to enumerate live hosts, then nmap's TCP SYN scan probes ports without completing handshakes, reducing traffic and IDS signatures compared with full connect scans, satisfying the stealth and speed constraints.
- ✗
Use netcat to perform a sequential port scan on each IP in the subnet
Why it's wrong here
Netcat opens one full TCP connection per port sequentially, so scanning 65,536 hosts is impractically slow and each completed handshake is logged. It is tempting because netcat is ubiquitous and needs no installation, and would be correct for manually probing a handful of known ports on a single host.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.