Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is preparing to perform an authenticated vulnerability scan of a network. Which THREE of the following are important considerations before starting the scan? (Select THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configuring the scanner to use the appropriate credentials

Authenticated scans require valid credentials to log into systems for deeper assessment. It's important to understand the risk of service disruption, ensure credentials have appropriate privileges, and obtain written authorization to avoid legal issues.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Using default community strings for SNMP

    Why it's wrong here

    Default SNMP community strings such as 'public' and 'private' are insecure legacy defaults, not a legitimate foundation for an authenticated scan. Authenticated scanning requires protocol-appropriate credentials (e.g., Active Directory, SSH, or database accounts) that provide read-level access to system state; attempting to use default SNMP strings is an unauthenticated attack technique limited to basic network discovery and would completely miss patch-level and configuration vulnerabilities that only appear after a successful login.

  • ✓

    Configuring the scanner to use the appropriate credentials

    Why this is correct

    Configuring the scanner with valid, appropriately privileged credentials is what makes the scan authenticated and is the single most important technical setup step. Without the correct credentials, the scanner reverts to an unauthenticated posture, producing incomplete results that overlook missing patches, insecure registry entries, local privilege escalation paths, and other authentication-dependent vulnerabilities. The credentials must be stored securely, scoped to the engagement, and granted only the permissions needed to enumerate software versions and system configuration without causing unintended changes.

  • ✓

    Ensuring the scan will not disrupt production services

    Why this is correct

    Authenticated scans can unintentionally disrupt production services because many vulnerability check plugins generate heavy load, perform active queries, or even crash the target. For example, scanning a database server with elevated credentials may execute queries that lock tables or exhaust memory, and Windows scan plugins that query WMI or the Remote Registry can cause resource spikes. A penetration tester must therefore confirm with system owners that the scan will run during an approved maintenance window, use throttled or 'safe' plugin settings, and avoid destructive checks to ensure business continuity.

  • ✗

    Selecting a random scan time to avoid detection

    Why it's wrong here

    Randomizing the scan time is a stealth technique associated with red-team operations or unauthenticated scanning where detection evasion matters. In an authenticated engagement, the tester has legitimate credentials and authorization, so there is no need to hide from security monitoring; in fact, predictable scheduling during maintenance windows lets the organization monitor, troubleshoot, and validate results. Choosing a random time would not improve scan accuracy and could increase business disruption by running at an uncoordinated moment, making this option irrelevant or counterproductive.

  • ✓

    Obtaining written authorization from the target organization

    Why this is correct

    Written authorization, typically in the form of a signed Rules of Engagement or penetration testing contract, is the absolute legal prerequisite for any credentialed scan. This document explicitly defines the scope, target systems, permitted credentials, and time windows; without it, using even valid accounts could be treated as unauthorized access under laws such as the CFAA or regional data-protection statutes. Obtaining this signed authorization before testing is not merely a best practice but a mandatory operational requirement that protects both the tester and the client.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.