Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

A penetration tester is writing a Python script to send a crafted TCP packet to a target. Which Python library should the tester use for low-level packet crafting and injection?

⚠ Common exam trap

CompTIA often tests the distinction between high-level protocol libraries (requests, impacket) and low-level packet crafting tools (scapy), trapping candidates who confuse 'network scripting' with 'raw packet manipulation'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

scapy

Scapy is the correct choice because it is a powerful Python library specifically designed for low-level packet crafting, manipulation, and injection. It allows the tester to construct arbitrary TCP packets at the raw socket level, control individual flags, sequence numbers, and payloads, and send them directly over the wire using Layer 2 or Layer 3 sockets. This makes it ideal for tasks like SYN flooding, TCP handshake manipulation, or custom protocol fuzzing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    requests

    Why it's wrong here

    The requests library operates at HTTP application layer, abstracting away TCP/IP headers entirely, so it cannot construct or inject raw packets with custom flags, sequence numbers or payloads. It is tempting because it excels at scripting HTTP interactions, such as sending crafted requests to web endpoints, which would be the correct choice for testing web application behaviour rather than packet-level manipulation.

  • ✗

    impacket

    Why it's wrong here

    Impacket provides protocol-level implementations (SMB, MSRPC, Kerberos) for network attacks and lateral movement, not raw frame construction. Scapy is the library for building and injecting arbitrary TCP/IP packets field by field. Impacket would be chosen when exploiting Windows protocols or executing remote command techniques.

  • ✓

    scapy

    Why this is correct

    Scapy lets the tester construct and inject raw TCP packets at layer 3/4, defining flags, sequence numbers and payloads directly. Socket alone lacks this crafting depth, and requests operates at HTTP level, so scapy fits low-level packet manipulation.

  • ✗

    socket

    Why it's wrong here

    The socket module builds TCP streams at the transport layer, so crafting arbitrary headers, flags or payloads requires manual byte assembly and raw sockets. Scapy is the intended library for packet crafting; socket suits basic client-server scripting.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.