mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is using Nmap to scan a…
A penetration tester is using Nmap to scan a target web server. The tester only wants to see which of the top 100 ports are open, but wants to minimize network traffic and time. Which Nmap command is most appropriate?
⚠ Common exam trap
Many candidates confuse `-p 1-100` (first 100 ports numerically) with `--top-ports 100` (most commonly open ports), leading them to choose option B, which misses high-numbered common ports like 443 (HTTPS) or 8080 (HTTP-alt).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
nmap -sV --top-ports 100 target
`--top-ports 100` instructs Nmap to scan only the 100 most commonly open ports, which minimizes network traffic and time compared to scanning all ports or a large range. The `-sV` flag enables version detection, which is not strictly required but is commonly used in information gathering; however, the key factor for minimizing traffic and time is the `--top-ports` option, which uses a statistically derived list to reduce scan scope.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
nmap -sS -p- target
Why it's wrong here
While -sS performs a SYN stealth scan that avoids completing TCP handshakes, the -p- flag instructs Nmap to enumerate every one of the 65,535 TCP ports. This creates a massive burst of packets and can take an extremely long time, especially without limiting the service-probing workload. The broad scan increases the chance of detection by IDS/IPS and is far more invasive than needed when the tester only needs to identify likely services on a web server.
- ✗
nmap -sT -p 1-100 target
Why it's wrong here
Using a numeric range manually forces Nmap to check ports 1 through 100 sequentially, which is both slow and ineffective because it excludes essential services such as HTTPS (443), MySQL (3306), and RDP (3389). The -sT flag makes matters worse by completing full TCP connections, generating far more connection-based log entries than a SYN scan. This approach wastes time on low-numbered ports while completely missing the most common web server services.
- ✗
nmap -sC -p 1-1000 target
Why it's wrong here
The -sC flag activates Nmap's default set of NSE scripts, which perform extensive banner grabbing, service enumeration, and vulnerability checks on every open port—substantially increasing network traffic and scan duration. Additionally, limiting to ports 1-1000 misses numerous high-numbered ports (e.g., 3306, 8080, 8443) that commonly host web applications and databases. The combination is both noisier and slower than necessary, and the script activity can crash fragile services or trigger security alerts.
- ✓
nmap -sV --top-ports 100 target
Why this is correct
The --top-ports 100 argument uses Nmap's frequency table to target the 100 most commonly open ports across real networks, including 80, 443, 22, 3389, 3306, and 8080. By pairing it with -sV, the tester gets service version enumeration only on those relevant ports, minimizing both time and packet count. This focuses on high-likelihood targets and avoids the wasted traffic of all-ports or broad-range scans. It is an ideal balance of speed and coverage for a quick web server assessment.
Go deeper
Related to this question
Learn chapter
SQL Injection: Union, Blind, Time-Based
Key term
Nmap
Nmap is a network scanning tool used to discover hosts, services, and operating systems on a computer network.
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.