mediumMultiple Choice
PT0-002 Practice Question: A penetration tester wants to identify hosts on a…
A penetration tester wants to identify hosts on a network that are running web servers on any TCP port, including non-standard ports. Which Nmap command is most efficient for this task?
⚠ Common exam trap
Many candidates choose `-sC` (default scripts) thinking it checks for web servers, but it only runs on the specified ports and doesn't detect services on non-standard ports.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
nmap -sV -p- target
`-sV` enables version detection to identify web server software, and `-p-` scans all 65535 TCP ports, including non-standard ones. This combination efficiently discovers web servers on any port without unnecessary overhead like OS detection or default script scanning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
nmap -sV -p- target
Why this is correct
The -p- flag directs Nmap to scan all 65,535 TCP ports, not just a default list, ensuring that web servers listening on unusual or non-standard ports are discovered. Coupled with -sV, Nmap performs service version detection by probing open ports and analyzing responses to identify the application and version, such as HTTP servers. This combination is the most thorough approach for the goal of identifying hosts running web services across the entire port range. Unlike OS detection or limited port scans, this directly reveals the service type.
- ✗
nmap -sC -p 80,443 target
Why it's wrong here
This command restricts the scan to only ports 80 and 443, which are the standard HTTP and HTTPS ports, but web servers often operate on higher ports such as 8080, 8000, or 8443 in development, proxy, or application-specific contexts. The -sC flag enables default NSE scripts, which are useful for vulnerability and configuration checks, but they do not extend the port list; they only run against the specified ports. Consequently, any web server on a non-standard port will be missed entirely, making this scan ineffective for comprehensive host discovery. The scan's narrow scope is its fundamental limitation, not the scripting.
- ✗
nmap -O -p- target
Why it's wrong here
While -p- ensures all TCP ports are scanned, the -O option triggers OS fingerprinting, which analyzes subtle TCP/IP stack behaviors to guess the operating system, not the services running on the hosts. OS detection does not interact with application-layer protocols, so it cannot identify a web server, which is the stated goal of the penetration test. This command would return OS guesses for live hosts but provide no information about HTTP/HTTPS services or the software version. Therefore, it is a mismatch for the objective of identifying web hosts, even though the port range is comprehensive.
- ✗
nmap -sT -p 8000,8080 target
Why it's wrong here
This command uses a full TCP connect scan (-sT) directed at only two alternative ports, 8000 and 8080, which are common but far from exhaustive for web servers. Modern applications may use ports like 8443, 8888, 9000, or any dynamic port, so targeting just two leaves many potential web services undiscovered. Additionally, -sT performs a full three-way handshake for each port, which is slower and more likely to be logged by IDS/IPS compared to a SYN stealth scan (-sS), though that is secondary to the port coverage issue. The combination of a limited port list and a slower scan method makes this option suboptimal for comprehensive host discovery.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.