Courseiva
easyMultiple Choice

PT0-002 Practice Question: A penetration tester wants to quickly capture and…

A penetration tester wants to quickly capture and analyze network packets during an internal test to identify unencrypted protocols. Which command-line tool is commonly used for packet capture on Linux?

⚠ Common exam trap

Watch out — candidates often confuse nmap's ability to detect open ports and services with packet capture, but nmap does not capture or display packet payloads, which is required for identifying unencrypted protocols.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

tcpdump

tcpdump is the standard command-line packet capture tool on Linux, allowing the tester to capture raw network packets and filter them by protocol (e.g., HTTP, FTP, Telnet) to identify unencrypted traffic. It uses libpcap to capture packets at the network interface level, making it ideal for quickly analyzing plaintext protocols during an internal penetration test.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    tcpdump

    Why this is correct

    tcpdump is the correct tool because it is a command-line packet sniffer that uses the libpcap library to capture network packets in real time or from a saved capture file. It supports Berkeley Packet Filter (BPF) syntax, enabling precise filtering by host, port, protocol, or even specific packet attributes. This makes it ideal for quickly capturing and analyzing traffic without altering the packets themselves, unlike active scanners.

  • ✗

    nslookup

    Why it's wrong here

    nslookup is incorrect for packet capture because it is a DNS diagnostic utility that sends DNS queries and displays name resolution results. It operates at the application layer and only queries DNS servers, generating its own lookups rather than passively observing network traffic. It cannot capture packets, and its output is limited to DNS records, not raw network frames.

  • ✗

    nmap

    Why it's wrong here

    nmap is incorrect because it is an active network scanning tool that sends crafted probes to discover hosts, open ports, and services. It relies on responses to these probes to infer network topology and vulnerabilities, so it modifies network behavior rather than simply capturing existing traffic. While nmap has a scripting engine, it does not perform passive packet capture; tcpdump is the appropriate utility for that role.

  • ✗

    netcat

    Why it's wrong here

    netcat is incorrect because it is a simple networking utility that reads and writes raw data over TCP or UDP connections, often used for port listening, connection testing, or transferring files. It can connect to or listen on a socket, but it does not intercept or analyze packets that are not destined for the application's own socket. To capture and analyze packets on an interface, you need a dedicated packet sniffer like tcpdump, which hooks into the network stack at a lower level.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.