Courseiva
mediumMultiple Choice

PT0-002 Practice Question: A penetration tester is using Nmap to scan a…

A penetration tester is using Nmap to scan a target web server. The tester only wants to see which of the top 100 ports are open, but wants to minimize network traffic and time. Which Nmap command is most appropriate?

⚠ Common exam trap

Many candidates confuse `-p 1-100` (first 100 ports numerically) with `--top-ports 100` (most commonly open ports), leading them to choose option B, which misses high-numbered common ports like 443 (HTTPS) or 8080 (HTTP-alt).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

nmap -sV --top-ports 100 target

`--top-ports 100` instructs Nmap to scan only the 100 most commonly open ports, which minimizes network traffic and time compared to scanning all ports or a large range. The `-sV` flag enables version detection, which is not strictly required but is commonly used in information gathering; however, the key factor for minimizing traffic and time is the `--top-ports` option, which uses a statistically derived list to reduce scan scope.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    nmap -sS -p- target

    Why it's wrong here

    While -sS performs a SYN stealth scan that avoids completing TCP handshakes, the -p- flag instructs Nmap to enumerate every one of the 65,535 TCP ports. This creates a massive burst of packets and can take an extremely long time, especially without limiting the service-probing workload. The broad scan increases the chance of detection by IDS/IPS and is far more invasive than needed when the tester only needs to identify likely services on a web server.

  • ✗

    nmap -sT -p 1-100 target

    Why it's wrong here

    Using a numeric range manually forces Nmap to check ports 1 through 100 sequentially, which is both slow and ineffective because it excludes essential services such as HTTPS (443), MySQL (3306), and RDP (3389). The -sT flag makes matters worse by completing full TCP connections, generating far more connection-based log entries than a SYN scan. This approach wastes time on low-numbered ports while completely missing the most common web server services.

  • ✗

    nmap -sC -p 1-1000 target

    Why it's wrong here

    The -sC flag activates Nmap's default set of NSE scripts, which perform extensive banner grabbing, service enumeration, and vulnerability checks on every open port—substantially increasing network traffic and scan duration. Additionally, limiting to ports 1-1000 misses numerous high-numbered ports (e.g., 3306, 8080, 8443) that commonly host web applications and databases. The combination is both noisier and slower than necessary, and the script activity can crash fragile services or trigger security alerts.

  • ✓

    nmap -sV --top-ports 100 target

    Why this is correct

    The --top-ports 100 argument uses Nmap's frequency table to target the 100 most commonly open ports across real networks, including 80, 443, 22, 3389, 3306, and 8080. By pairing it with -sV, the tester gets service version enumeration only on those relevant ports, minimizing both time and packet count. This focuses on high-likelihood targets and avoids the wasted traffic of all-ports or broad-range scans. It is an ideal balance of speed and coverage for a quick web server assessment.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.