PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is using Nmap to perform an aggressive scan of a target. Which command combines OS detection, version detection, script scanning, and traceroute?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
nmap -A target
The -A flag enables aggressive scanning which includes OS detection (-O), version detection (-sV), script scanning (-sC), and traceroute (--traceroute).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
nmap -sV -O target
Why it's wrong here
The -sV flag performs service/version detection by connecting to open ports and interrogating banners, and -O triggers OS fingerprinting via TCP/IP behavior, but together they omit the Nmap Scripting Engine and traceroute. An -A scan would include these two plus default NSE scripts and --traceroute, so this command captures only part of the aggressive feature set. Without script scanning, you miss vulnerability checks and service enumeration that -A would provide, making it an incomplete answer.
- ✓
nmap -A target
Why this is correct
The -A flag is Nmap's built-in alias for aggressive scanning, expanding to -O (OS detection), -sV (version detection), -sC (default NSE scripts), and --traceroute. This single command gives a penetration tester the full suite of enumeration techniques in one pass, which is exactly what the question's 'aggressive' wording refers to. Keep in mind that -A can be intrusive and generate significant network traffic, but that is the intended trade-off for thorough reconnaissance.
- ✗
nmap -sC -O target
Why it's wrong here
While -sC (or --script=default) invokes a collection of commonly used NSE scripts and -O enables OS detection, this command never runs version detection, so scripts may attempt to work with incomplete service information. It also omits traceroute, which is part of the -A aggregation. Thus the combination is a partial aggressive profile — useful for quick scripted enumeration but not the full feature set implied by 'aggressive' in the question.
- ✗
nmap -T4 -sV target
Why it's wrong here
The -T4 option selects the 'aggressive' timing template, which speeds up packet transmission and timeout values, but this is purely a performance tuning parameter, not a feature toggle. Combined with -sV, the command only performs version detection and yields no OS fingerprinting, NSE script execution, or traceroute. The term 'aggressive' in the answer options refers to the -A flag's feature bundle, not the timing template level, so this command is missing the core enumeration capabilities.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.