mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is reviewing a Bash script…
A penetration tester is reviewing a Bash script that uses 'nmap' with the '-sC' and '-sV' flags. The script runs the scan and saves the output to a text file. Later, the tester uses 'grep' to extract lines containing 'open'. What is the primary purpose of this script?
⚠ Common exam trap
CompTIA often tests the distinction between default NSE scripts (service enumeration) and vulnerability-specific scripts (e.g., 'vuln'), leading candidates to mistakenly think '-sC' implies vulnerability scanning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identify all open ports and services running on them
The '-sC' flag runs default NSE scripts (which perform service enumeration and basic checks), and '-sV' enables version detection. Together, they identify open ports and the services/versions running on them. The subsequent 'grep' for 'open' extracts lines showing open ports, confirming the primary purpose is to enumerate open ports and their associated services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Identify all open ports and services running on them
Why this is correct
The command combines `-sC` (default NSE scripts) with `-sV` (service/version detection), and the pipeline's grep step filters the output for open ports and associated service banners. This is a standard reconnaissance technique to enumerate listening TCP services, which is exactly what the correct answer describes. Default scripts augment version data with service-specific details, but the primary goal is mapping the attack surface, not deep vulnerability assessment.
- ✗
Perform a vulnerability scan using NSE scripts
Why it's wrong here
Although `-sC` invokes the default category of NSE scripts, these are safe, non-intrusive scripts designed to support enumeration—they do not target specific CVEs. A true vulnerability scan via NSE requires explicitly selecting categories like `vuln` or `exploit` (e.g., `--script vuln`), which is absent here. Furthermore, the grep step is used to extract port and service lines, indicating that the intended output is discovery-focused rather than a vulnerability report.
- ✗
Detect the operating system of the target
Why it's wrong here
OS fingerprinting in nmap requires the `-O` flag, which sends specially crafted TCP/IP probes to analyze stack behavior. The script only uses `-sC` and `-sV`; these flags perform version detection and script scanning but do not enable OS detection. Without `-O`, nmap cannot deduplicate or identify the underlying operating system with confidence, so this option cannot be the script's purpose.
- ✗
Perform a stealthy SYN scan
Why it's wrong here
A stealthy SYN scan (half-open scan) is a specific scanning technique enabled by `-sS`, which sends SYN packets without completing the TCP handshake. The script in question uses `-sC` and `-sV`, which are not scan types at all—they add version detection and default NSE scripts to whatever scan type is implied. If the script lacks an explicit scan type and is run without root privileges, it may default to a full TCP connect scan, which is not stealthy; thus this option misidentifies both the flags and the likely behavior.
Go deeper
Related to this question
Learn chapter
Post-Exploitation File Transfer Techniques
Key term
Enumeration
Enumeration is the systematic process of extracting detailed information about a target system, such as user accounts, network shares, services, and configurations, used during the reconnaissance phase of a security assessment.
Key term
Bash script
A Bash script is a text file containing a sequence of commands for the Unix shell Bash, allowing users to automate repetitive tasks and streamline system administration on Linux and macOS.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.