PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester runs a SYN scan against a target and receives SYN-ACK responses from several ports. The tester then runs version detection on those ports. What is the primary purpose of version detection?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To identify the software and version running on open ports
Version detection (-sV) in Nmap identifies the specific software and version running on open ports, helping assess potential vulnerabilities and plan further exploitation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To identify the operating system of the target
Why it's wrong here
The purpose of a SYN scan is to discover open ports by observing SYN-ACK responses, not to fingerprint the operating system. OS detection requires dedicated techniques such as sending malformed or atypical TCP/IP packets and analyzing stack behavior, as implemented in Nmap's -O flag. Version detection, conversely, probes the service on an open port to reveal application and version details. Therefore, while a SYN scan may incidentally reveal some OS hints from the initial TTL, it does not perform OS identification.
- ✗
To perform a vulnerability scan
Why it's wrong here
Version detection only identifies the identity and version of a service; it does not compare that information against vulnerability databases or actively test for exploitability. A vulnerability scan, such as Nessus or OpenVAS, combines port scanning, version identification, and a large set of plugins to assess security weaknesses. Running a SYN scan in combination with version detection gives you a service inventory, not a vulnerability assessment. Thus, this answer incorrectly conflates enumeration with vulnerability analysis.
- ✗
To determine if the host is online
Why it's wrong here
A SYN scan's primary goal is to determine which TCP ports are open, filtered, or closed, not to confirm host availability. Host discovery techniques, such as ICMP echo requests, ARP scans, or TCP ACK probes to a specific port, are designed to answer 'is the host alive?' A SYN scan will likely receive a response from an open port if the host is up, but that is a side effect, not the intended purpose of version detection. In fact, version detection runs only after the port is known to be open, so it presupposes the host is online.
- ✓
To identify the software and version running on open ports
Why this is correct
Version detection is a post-scan enumeration step that sends specially crafted probes to open ports and analyzes the responses to determine the exact software and version, such as 'OpenSSH 8.2p1 Ubuntu 4ubuntu0.5' on port 22. This is typically performed using a tool like Nmap with the -sV flag, which may also try to infer service protocol and back-end. Unlike OS detection, it focuses on the application layer, and unlike vulnerability scanning, it does not evaluate security. The information gathered is essential for matching services to known CVEs and planning further exploitation.
Visual reference
Go deeper
Related to this question
Learn chapter
Penetration Testing Methodology
Key term
Exploitation
Exploitation is the act of using a vulnerability or weakness in a system, network, or application to gain unauthorized access, cause damage, or extract data.
Key term
Nmap
Nmap is a network scanning tool used to discover hosts, services, and operating systems on a computer network.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.