PT0-002 Vulnerability Discovery and Analysis Practice Question
A penetration tester is writing a Python script to send a crafted TCP packet to a target. Which Python library should the tester use for low-level packet crafting and injection?
⚠ Common exam trap
CompTIA often tests the distinction between high-level protocol libraries (requests, impacket) and low-level packet crafting tools (scapy), trapping candidates who confuse 'network scripting' with 'raw packet manipulation'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
scapy
Scapy is the correct choice because it is a powerful Python library specifically designed for low-level packet crafting, manipulation, and injection. It allows the tester to construct arbitrary TCP packets at the raw socket level, control individual flags, sequence numbers, and payloads, and send them directly over the wire using Layer 2 or Layer 3 sockets. This makes it ideal for tasks like SYN flooding, TCP handshake manipulation, or custom protocol fuzzing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
requests
Why it's wrong here
The requests library operates at HTTP application layer, abstracting away TCP/IP headers entirely, so it cannot construct or inject raw packets with custom flags, sequence numbers or payloads. It is tempting because it excels at scripting HTTP interactions, such as sending crafted requests to web endpoints, which would be the correct choice for testing web application behaviour rather than packet-level manipulation.
- ✗
impacket
Why it's wrong here
Impacket provides protocol-level implementations (SMB, MSRPC, Kerberos) for network attacks and lateral movement, not raw frame construction. Scapy is the library for building and injecting arbitrary TCP/IP packets field by field. Impacket would be chosen when exploiting Windows protocols or executing remote command techniques.
- ✓
scapy
Why this is correct
Scapy lets the tester construct and inject raw TCP packets at layer 3/4, defining flags, sequence numbers and payloads directly. Socket alone lacks this crafting depth, and requests operates at HTTP level, so scapy fits low-level packet manipulation.
- ✗
socket
Why it's wrong here
The socket module builds TCP streams at the transport layer, so crafting arbitrary headers, flags or payloads requires manual byte assembly and raw sockets. Scapy is the intended library for packet crafting; socket suits basic client-server scripting.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.