PT0-002 Vulnerability Discovery and Analysis Practice Question
A penetration tester needs to identify live hosts and open ports on a target network. Which tool is most appropriate for this task?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Nmap
Nmap is the standard tool for network discovery and port scanning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Burp Suite
Why it's wrong here
Burp Suite is an intercepting proxy engineered specifically for web application security testing. It operates at the HTTP/HTTPS application layer, enabling request modification, session manipulation, and web-app-specific vulnerability scanning, but it cannot craft arbitrary TCP/IP packets to probe network hosts. Without an existing target URL or web session, Burp has no mechanism for raw SYN scans, ICMP pings, or ARP discovery, so it cannot realistically be used for general live-host identification. Its scanning modules run through the proxy and require an established web resource, making it fundamentally unsuitable for the network-layer task described.
- ✓
Nmap
Why this is correct
Nmap is the canonical tool for network discovery and security auditing because it actively crafts raw IP packets to determine which hosts are up and which ports are open on those hosts. It supports host discovery via ARP, ICMP, TCP ACK, and overhead protocols, and port scanning via techniques like SYN scan (-sS), TCP connect (-sT), and UDP scan (-sU), each of which sends controlled probes and interprets the responses. For example, a SYN-ACK reply indicates an open port, while an RST indicates closed or filtered depending on the context. Its ability to combine multi-layered probing and response analysis makes it the correct choice for this penetration testing stage.
- ✗
Metasploit
Why it's wrong here
Metasploit is primarily a penetration testing exploitation framework that delivers shellcode and manages post-exploitation activities, not a dedicated host discovery scanner. While Metasploit has auxiliary modules (e.g., auxiliary/scanner/portscan/tcp) that can perform basic port scans, they are rarely as comprehensive or as efficient as Nmap's packet-crafting engine, and the framework's real value lies in verifying and exploiting vulnerabilities after open ports have been identified. Running Nmap from within Metasploit is common, but that uses Nmap's engine; relying on Metasploit alone for live host and open port identification would be counterproductive, as its scanners lack the full range of TCP/IP option control and OS fingerprinting techniques that Nmap natively provides.
- ✗
Wireshark
Why it's wrong here
Wireshark is a packet sniffer and protocol analyzer that passively captures and decodes network traffic already present on the wire or air interface. It cannot actively send probes, generate SYN packets, or perform an interactive ping sweep, so it has no direct method to 'ask' a network which hosts are alive or which ports are listening. To discover open ports, a scanner like Nmap is needed; Wireshark might be used to observe the resulting scan traffic to validate packet crafting or inspect responses, but it is not itself an active scanning tool. This passive-only capability means that if no traffic has been generated to a target, Wireshark will show no information about live hosts or open ports.
Go deeper
Related to this question
Learn chapter
Network Exploitation
Key term
Nmap
Nmap is a network scanning tool used to discover hosts, services, and operating systems on a computer network.
Key term
Active reconnaissance
Active reconnaissance is the process of directly interacting with a target system or network to gather information, often through scanning and probing.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.