Courseiva
easyMultiple Choice

PT0-002 Practice Question: A penetration tester wants to perform a slow and…

A penetration tester wants to perform a slow and stealthy port scan to avoid intrusion detection systems. Which Nmap option should be used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

-T0

The -T0 option sets the timing template to Paranoid, which is extremely slow and avoids IDS detection. -O is for OS detection, -sV for version detection, and -A for aggressive scan.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    -O

    Why it's wrong here

    -O is the Nmap option for remote OS fingerprinting, which works by sending specially crafted TCP, UDP, and ICMP probes to observe how the target responds to unusual packet sequences. This technique relies on active measurement and often creates distinctive patterns that intrusion detection systems can flag, making it more detectable rather than stealthier. It does not regulate the speed of the scan or introduce delays between packets; timing is governed by independent timing templates, so -O is not a valid choice for slow and stealthy execution.

  • ✗

    -A

    Why it's wrong here

    -A is Nmap's aggressive scan mode that bundles OS detection, version detection, default script scanning, and traceroute into a single invocation. This combination dramatically increases the volume and variety of traffic sent to the target, often triggering alerts on intrusion detection and prevention systems, and it prioritizes breadth and speed over concealment. It does not apply slow timing parameters; in fact, its default behavior is to run concurrently and aggressively, which is the antithesis of a stealthy, slow-paced scan, so it is not the correct option.

  • ✓

    -T0

    Why this is correct

    -T0 is Nmap's Paranoid timing template, which intentionally introduces extreme delays between successive probes, typically waiting 300 seconds (5 minutes) before sending the next packet. This serialized, near-constant pacing is designed to stay well below the threshold that most real-time intrusion detection systems use for alerting, making it the slowest and most stealthy timing mode available. Its entire purpose is to minimize network footprint and avoid rate-based detection, directly fulfilling the penetration tester's requirement for a slow and stealthy scan, so it is the correct answer.

  • ✗

    -sV

    Why it's wrong here

    -sV is an Nmap flag that enables service/version detection, instructing the tool to connect to open ports and interrogate banners or protocols to identify the exact software and version running. This process actively sends application-layer probes, generating noticeable traffic and increasing the scan's footprint, which is the opposite of stealth. It has no effect on packet pacing or timing, as timing is controlled separately via timing templates (-T0 through -T5) or explicit delay parameters, so -sV does not answer the request for a slow and stealthy approach.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.