Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

A penetration tester is writing a Bash script to automate scanning of multiple subnets with Nmap and parse the output. Which three features are commonly used in such a script? (Choose THREE.)

⚠ Common exam trap

It's easy for candidates to confuse cross-platform scripting features (like PowerShell cmdlets) with Bash-native constructs, or mistakenly think PySerial is relevant for network scanning, when the exam focuses on Bash-specific tools (for loops, grep) and Nmap's structured output (-oX) for automation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Nmap XML output (-oX)

Option B (Nmap XML output -oX) is correct because -oX writes scan results to a machine-readable XML file, which a Bash script can then parse reliably with tools like grep, awk, or xmllint. Option C (For loop) is correct because a Bash for loop iterates over a list of subnets or target ranges, invoking Nmap once per subnet to automate the scanning process. Option D (grep) is correct because grep filters the Nmap output (or XML file) for specific patterns such as open ports or host states, enabling the script to extract and act on relevant results. Option A (PowerShell cmdlets) does not belong because cmdlets are PowerShell constructs, not Bash features, and would not run natively in a Bash script. Option E (PySerial) does not belong because PySerial is a Python library for serial-port communication, unrelated to Nmap scanning or Bash scripting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    PowerShell cmdlets

    Why it's wrong here

    PowerShell cmdlets are not native to Bash, and a Bash script cannot directly execute them without invoking the powershell.exe or pwsh interpreter as an external process. This would add unnecessary overhead and platform dependencies, breaking the portability of a Linux-centric Bash automation script. PowerShell is a separate scripting language with its own pipeline, so using cmdlets would require rewriting the script entirely.

  • ✓

    Nmap XML output (-oX)

    Why this is correct

    Nmap's -oX flag instructs the tool to write results in XML format, which is structured and machine-parseable, making it ideal for automated post-processing in a Bash script. Unlike plain text, XML can be reliably queried with tools such as xmlstarlet or xmllint to extract hosts, open ports, and service versions, enabling dynamic follow-up actions. This is the correct option because it is a native Nmap feature designed for automation.

  • ✓

    For loop

    Why this is correct

    A for loop in Bash provides the iterative control structure needed to automate scanning across multiple subnets. For example, one can define an array of subnet ranges and loop through them, calling nmap on each iteration. This approach scales the automation and allows the script to handle a variable number of targets without hard-coding individual commands.

  • ✓

    grep

    Why this is correct

    grep is a powerful text-filtering utility that can be used in a Bash pipeline to pull key data from Nmap's grepable output format (-oG) or from standard text logs. For instance, grep can extract lines containing 'open' to identify active ports, or parse out IP addresses with regular expressions. It is correct because it gives the penetration tester a lightweight, native Bash method to separate useful scan results from noise.

  • ✗

    PySerial

    Why it's wrong here

    PySerial is a Python library designed for serial communication over RS-232 and other serial protocols, not for parsing Nmap scan results. It has no functions for handling XML, text logs, or network scan output, and using it would require moving the automation into Python rather than Bash. This option is wrong because it is fundamentally unrelated to the task of processing Nmap data.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.