PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is performing service enumeration on a discovered host and wants to grab banners from open ports to identify the exact software and version running. Which of the following command-line tools would be most appropriate for this task?
⚠ Common exam trap
CompTIA Pentest+ tests the distinction between general connectivity tools (ping, traceroute) and service-specific tools (nc, telnet, nmap -sV), expecting candidates to recognize that only raw TCP connection tools can perform banner grabbing on arbitrary ports.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
nc -v target.com 22
`nc -v target.com 22` uses Netcat in verbose mode to connect to port 22 on the target, which triggers the SSH server to send its banner (e.g., "SSH-2.0-OpenSSH_8.9p1"). This banner directly reveals the exact software and version running on that port, making it ideal for service enumeration and banner grabbing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
traceroute target.com
Why it's wrong here
traceroute maps the network path between hosts by varying TTL values, sending no application-layer payload that elicits a service banner. It is tempting because it does probe the target, and would be correct when the task is mapping intermediate routers or diagnosing routing hops rather than identifying listening software versions.
- ✗
ping target.com
Why it's wrong here
ping sends ICMP echo requests to test host reachability and receives echo replies, which carry no software or version information. It is tempting because it confirms the target is alive, and would be correct for verifying connectivity or measuring round-trip latency before deeper enumeration begins.
- ✗
curl http://target.com
Why it's wrong here
curl fetches an HTTP resource and returns the response body, not the raw service banner; it also speaks only HTTP, so it cannot enumerate the other open ports. It is tempting because it does connect to web services, and would be correct for retrieving a specific page or testing an HTTP endpoint.
- ✓
nc -v target.com 22
Why this is correct
Netcat's verbose flag prints the service banner returned on connect, so nc -v target.com 22 reveals the SSH software and version string. It satisfies the banner-grabbing requirement directly on a chosen port without extra scripting.
Go deeper
Related to this question
Learn chapter
Phishing Campaigns in Penetration Testing
Key term
Enumeration
Enumeration is the systematic process of extracting detailed information about a target system, such as user accounts, network shares, services, and configurations, used during the reconnaissance phase of a security assessment.
Key term
Banner grabbing
Banner grabbing is the process of connecting to a remote service to capture the banner it sends, which often reveals software type and version for reconnaissance.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.