Courseiva
mediumMultiple Choice

PT0-002 Practice Question: A penetration tester is reviewing a Bash script…

A penetration tester is reviewing a Bash script that uses 'nmap' with the '-sC' and '-sV' flags. The script runs the scan and saves the output to a text file. Later, the tester uses 'grep' to extract lines containing 'open'. What is the primary purpose of this script?

⚠ Common exam trap

CompTIA often tests the distinction between default NSE scripts (service enumeration) and vulnerability-specific scripts (e.g., 'vuln'), leading candidates to mistakenly think '-sC' implies vulnerability scanning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identify all open ports and services running on them

The '-sC' flag runs default NSE scripts (which perform service enumeration and basic checks), and '-sV' enables version detection. Together, they identify open ports and the services/versions running on them. The subsequent 'grep' for 'open' extracts lines showing open ports, confirming the primary purpose is to enumerate open ports and their associated services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Identify all open ports and services running on them

    Why this is correct

    The command combines `-sC` (default NSE scripts) with `-sV` (service/version detection), and the pipeline's grep step filters the output for open ports and associated service banners. This is a standard reconnaissance technique to enumerate listening TCP services, which is exactly what the correct answer describes. Default scripts augment version data with service-specific details, but the primary goal is mapping the attack surface, not deep vulnerability assessment.

  • ✗

    Perform a vulnerability scan using NSE scripts

    Why it's wrong here

    Although `-sC` invokes the default category of NSE scripts, these are safe, non-intrusive scripts designed to support enumeration—they do not target specific CVEs. A true vulnerability scan via NSE requires explicitly selecting categories like `vuln` or `exploit` (e.g., `--script vuln`), which is absent here. Furthermore, the grep step is used to extract port and service lines, indicating that the intended output is discovery-focused rather than a vulnerability report.

  • ✗

    Detect the operating system of the target

    Why it's wrong here

    OS fingerprinting in nmap requires the `-O` flag, which sends specially crafted TCP/IP probes to analyze stack behavior. The script only uses `-sC` and `-sV`; these flags perform version detection and script scanning but do not enable OS detection. Without `-O`, nmap cannot deduplicate or identify the underlying operating system with confidence, so this option cannot be the script's purpose.

  • ✗

    Perform a stealthy SYN scan

    Why it's wrong here

    A stealthy SYN scan (half-open scan) is a specific scanning technique enabled by `-sS`, which sends SYN packets without completing the TCP handshake. The script in question uses `-sC` and `-sV`, which are not scan types at all—they add version detection and default NSE scripts to whatever scan type is implied. If the script lacks an explicit scan type and is run without root privileges, it may default to a full TCP connect scan, which is not stealthy; thus this option misidentifies both the flags and the likely behavior.

Go deeper

Related to this question

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.