easyMultiple Choice
PT0-002 Practice Question: A penetration tester wants to identify the…
A penetration tester wants to identify the operating system of a remote host without sending any traffic to the target network. Which of the following techniques is most effective for this purpose?
⚠ Common exam trap
Test-takers frequently assume passive OS identification requires active scanning tools like nmap, overlooking that Shodan provides a passive, historical data source that avoids generating any traffic to the target.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Shodan to search for the host's IP address and examine the service banners.
Shodan is a search engine that indexes service banners and metadata from internet-connected devices. By querying Shodan for the target's IP address, the tester can retrieve previously collected OS information without sending any packets to the target, satisfying the 'no traffic' constraint.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform an nmap OS fingerprint scan on the host.
Why it's wrong here
An nmap OS fingerprint scan transmits probes to the target, directly violating the requirement to send no traffic to the target network. It is tempting because OS fingerprinting is the definitive active technique, and it would be correct when the tester is authorised to interact directly with the host.
- ✓
Use Shodan to search for the host's IP address and examine the service banners.
Why this is correct
Shodan's pre-collected banners and service fingerprints let the tester infer the host's operating system from cached scan data, satisfying the passive-only constraint since no packets reach the target network. Active fingerprinting techniques would generate traffic and violate the requirement.
- ✗
Send a ping sweep to the host's network segment.
Why it's wrong here
A ping sweep sends ICMP echo requests into the target segment, which is traffic to the target network and is therefore excluded by the scenario's constraint. It is tempting because ping sweeps are a quick way to enumerate live hosts, and one would be correct during an authorised active discovery phase.
- ✗
Use ARP scanning to discover the host's MAC address and look up the vendor.
Why it's wrong here
ARP scanning broadcasts frames onto the local segment, which is traffic to the target network, and MAC vendor lookup reveals only the NIC manufacturer, not the operating system. It is tempting because ARP is unauthenticated and fast on a LAN, and it would suit mapping local hosts when active traffic is permitted.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.