Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is performing service enumeration on a discovered host and wants to grab banners from open ports to identify the exact software and version running. Which of the following command-line tools would be most appropriate for this task?

⚠ Common exam trap

CompTIA Pentest+ tests the distinction between general connectivity tools (ping, traceroute) and service-specific tools (nc, telnet, nmap -sV), expecting candidates to recognize that only raw TCP connection tools can perform banner grabbing on arbitrary ports.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

nc -v target.com 22

`nc -v target.com 22` uses Netcat in verbose mode to connect to port 22 on the target, which triggers the SSH server to send its banner (e.g., "SSH-2.0-OpenSSH_8.9p1"). This banner directly reveals the exact software and version running on that port, making it ideal for service enumeration and banner grabbing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    traceroute target.com

    Why it's wrong here

    traceroute maps the network path between hosts by varying TTL values, sending no application-layer payload that elicits a service banner. It is tempting because it does probe the target, and would be correct when the task is mapping intermediate routers or diagnosing routing hops rather than identifying listening software versions.

  • ✗

    ping target.com

    Why it's wrong here

    ping sends ICMP echo requests to test host reachability and receives echo replies, which carry no software or version information. It is tempting because it confirms the target is alive, and would be correct for verifying connectivity or measuring round-trip latency before deeper enumeration begins.

  • ✗

    curl http://target.com

    Why it's wrong here

    curl fetches an HTTP resource and returns the response body, not the raw service banner; it also speaks only HTTP, so it cannot enumerate the other open ports. It is tempting because it does connect to web services, and would be correct for retrieving a specific page or testing an HTTP endpoint.

  • ✓

    nc -v target.com 22

    Why this is correct

    Netcat's verbose flag prints the service banner returned on connect, so nc -v target.com 22 reveals the SSH software and version string. It satisfies the banner-grabbing requirement directly on a chosen port without extra scripting.

Go deeper

Related to this question

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.