Courseiva
easyMultiple Choice

PT0-002 Practice Question: A penetration tester needs to enumerate active…

A penetration tester needs to enumerate active hosts and open ports on a network segment with minimal network traffic. Which tool should the tester use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Nmap

Nmap with -sn (ping scan) is designed for host discovery using minimal network traffic. Hydra is for password cracking, Metasploit is an exploitation framework, and Nikto is a web server scanner.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Nmap

    Why this is correct

    Nmap is the industry-standard tool for active host discovery and port enumeration. The -sn option performs a ping sweep using ICMP, TCP SYN, or UDP probes to identify live hosts with minimal traffic, making it ideal for the early reconnaissance phase of a penetration test. Its ability to then map open ports and services on those hosts makes it the definitive choice for this task.

  • ✗

    Metasploit

    Why it's wrong here

    Metasploit is a comprehensive exploitation framework designed to deliver payloads and execute post-exploitation modules after a target is known to be vulnerable. While it includes auxiliary scanner modules, these require you to already specify a host or IP range and are not a primary mechanism for active host discovery. Using Metasploit solely to enumerate live hosts adds unnecessary complexity and risk, as its core purpose is exploitation, not reconnaissance.

  • ✗

    Nikto

    Why it's wrong here

    Nikto is a purpose-built web server vulnerability scanner that focuses on HTTP/HTTPS testing, such as identifying outdated server software, risky CGI files, and default credentials. It sends a barrage of HTTP requests to a single web server, meaning it cannot discover active hosts across a network substrate. Therefore, it plays no role in the host-discovery phase and is applied only after a web server has already been located.

  • ✗

    Hydra

    Why it's wrong here

    Hydra is a network authentication brute-forcing tool that performs dictionary attacks against login services like SSH, FTP, RDP, and HTTP forms. To use Hydra effectively, you must first know the target's IP address and the open port of a running authentication service, because Hydra does not scan for open ports or live hosts. Employing Hydra for host enumeration is fundamentally wrong, as it assumes discovery has already occurred and instead targets credentials.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.