Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester runs a SYN scan against a target and receives SYN-ACK responses from several ports. The tester then runs version detection on those ports. What is the primary purpose of version detection?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To identify the software and version running on open ports

Version detection (-sV) in Nmap identifies the specific software and version running on open ports, helping assess potential vulnerabilities and plan further exploitation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To identify the operating system of the target

    Why it's wrong here

    The purpose of a SYN scan is to discover open ports by observing SYN-ACK responses, not to fingerprint the operating system. OS detection requires dedicated techniques such as sending malformed or atypical TCP/IP packets and analyzing stack behavior, as implemented in Nmap's -O flag. Version detection, conversely, probes the service on an open port to reveal application and version details. Therefore, while a SYN scan may incidentally reveal some OS hints from the initial TTL, it does not perform OS identification.

  • ✗

    To perform a vulnerability scan

    Why it's wrong here

    Version detection only identifies the identity and version of a service; it does not compare that information against vulnerability databases or actively test for exploitability. A vulnerability scan, such as Nessus or OpenVAS, combines port scanning, version identification, and a large set of plugins to assess security weaknesses. Running a SYN scan in combination with version detection gives you a service inventory, not a vulnerability assessment. Thus, this answer incorrectly conflates enumeration with vulnerability analysis.

  • ✗

    To determine if the host is online

    Why it's wrong here

    A SYN scan's primary goal is to determine which TCP ports are open, filtered, or closed, not to confirm host availability. Host discovery techniques, such as ICMP echo requests, ARP scans, or TCP ACK probes to a specific port, are designed to answer 'is the host alive?' A SYN scan will likely receive a response from an open port if the host is up, but that is a side effect, not the intended purpose of version detection. In fact, version detection runs only after the port is known to be open, so it presupposes the host is online.

  • ✓

    To identify the software and version running on open ports

    Why this is correct

    Version detection is a post-scan enumeration step that sends specially crafted probes to open ports and analyzes the responses to determine the exact software and version, such as 'OpenSSH 8.2p1 Ubuntu 4ubuntu0.5' on port 22. This is typically performed using a tool like Nmap with the -sV flag, which may also try to infer service protocol and back-end. Unlike OS detection, it focuses on the application layer, and unlike vulnerability scanning, it does not evaluate security. The information gathered is essential for matching services to known CVEs and planning further exploitation.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.