Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is tasked with performing an authenticated vulnerability scan of a Windows network. The tester has domain admin credentials. Which tool is most appropriate for this task?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Nessus

Nessus supports authenticated scanning using credentials (e.g., domain admin) to perform deep vulnerability assessment of Windows systems, including missing patches and insecure configurations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Nikto

    Why it's wrong here

    Nikto is a web server scanner that focuses on identifying vulnerable files, misconfigurations, and known exploits on web servers. It uses a database of signatures for HTTP-based checks and cannot authenticate to Windows hosts for local OS-level vulnerability enumeration. Even if given credentials, Nikto only performs web-focused checks (e.g., CGI directories, outdated server software), not comprehensive authenticated Windows host vulnerability assessment.

  • ✗

    Nmap

    Why it's wrong here

    Nmap is a network mapper and port scanner with a scripting engine (NSE) that can detect services and versions, and some scripts do check for known CVEs, but it lacks a unified vulnerability management database and cannot perform authenticated registry/configuration scanning on Windows. Credentialed scans in Nmap are limited to things like SMB enumeration with specific scripts, not a holistic patch-level and configuration assessment like Nessus.

  • ✗

    theHarvester

    Why it's wrong here

    theHarvester is a passive OSINT reconnaissance tool used to gather emails, subdomains, hosts, and employee names from public sources like search engines, PGP key servers, and SHODAN. It does not interact with target systems directly, so it cannot perform authenticated scanning or vulnerability discovery; it is used in the early footprinting phase, not vulnerability assessment.

  • ✓

    Nessus

    Why this is correct

    Nessus is a commercial vulnerability scanner that supports credentialed scans via protocols like SSH, WinRM, or SMB, enabling deep assessment of Windows patch levels, service configurations, and custom software. It uses a comprehensive plugin database (e.g., via Nessus or the free Nessus Essentials) to map system state to known vulnerabilities, including missing patches, weak permissions, and policy violations. For authenticated Windows scanning, it connects with provided credentials (local or domain) to query WMI and the registry, making it the correct tool for this task.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.