easyMultiple Choice
PT0-002 Practice Question: A penetration tester is reviewing a Bash script…
A penetration tester is reviewing a Bash script that contains the following command: 'openssl s_client -connect target:443 -servername target 2>/dev/null | openssl x509 -noout -text'. What is the primary purpose of this command?
⚠ Common exam trap
Many exam-takers confuse certificate retrieval with cipher suite testing or assume any use of `openssl s_client` implies an attack, when in fact the command is a standard diagnostic tool for inspecting certificate content.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Extract the SSL certificate in text form.
The command uses `openssl s_client` to establish a TLS connection to `target:443` and then pipes the certificate output to `openssl x509 -noout -text`, which decodes and prints the certificate in human-readable text form. The primary purpose is to retrieve and display the SSL/TLS certificate details (e.g., issuer, subject, validity dates, SANs) for inspection, not to attack or test cipher suites.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Extract the SSL certificate in text form.
Why this is correct
The command chain `openssl s_client -connect host:port -showcerts | openssl x509 -noout -text` establishes a real TLS connection to the specified server and pipes the server's presented certificate (or chain) into `x509 -text`, which decodes the DER-encoded fields and displays them in a human-readable, structured text format. This is a standard, quick way to inspect certificate details such as subject, issuer, validity period, and extensions.
- ✗
Perform a man-in-the-middle attack.
Why it's wrong here
A man-in-the-middle (MITM) attack requires inserting an attacker-controlled proxy between the client and server, typically via ARP spoofing, DNS spoofing, or transparent proxying, and then relaying and possibly modifying traffic. The given command only creates a direct, one-off TLS connection to the target host to retrieve its certificate; it does not intercept traffic from other clients or establish any relay mechanism.
- ✗
Test for weak cipher suites.
Why it's wrong here
Testing for weak cipher suites requires actively attempting to negotiate a TLS handshake using a list of candidate ciphers (e.g., via `openssl s_client -cipher` or automated tools like `sslscan` or `nmap --script ssl-enum-ciphers`). The command in question only fetches the static certificate presented during the handshake; it does not request or analyze the server's supported cipher list, so it cannot reveal weak or outdated cipher support.
- ✗
Verify the certificate's revocation status.
Why it's wrong here
Verifying a certificate's revocation status requires querying external trust sources, either by retrieving and parsing a Certificate Revocation List (CRL) from the issuer's distribution point or by sending an Online Certificate Status Protocol (OCSP) request to the designated responder. The command `openssl s_client | openssl x509 -text` merely decodes and prints the certificate's local fields; it makes no network calls to CRL or OCSP endpoints, so it cannot confirm whether the certificate has been revoked.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.