Courseiva
easyMultiple Choice

PT0-002 Practice Question: A tester is using the following Nmap command:…

A tester is using the following Nmap command: nmap -sC -sV -p 1-65535 target_ip. What is the primary purpose of the -sC option?

⚠ Common exam trap

Test-takers frequently confuse -sC with -sV or -sS, because all three options start with 's' and are commonly used together, but each has a distinct function that must be memorized for the exam.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use default scripts

The -sC option in Nmap is equivalent to --script=default, which runs a collection of common, non-intrusive enumeration scripts against the target. These scripts perform tasks such as service banner grabbing, HTTP title extraction, and SSL/TLS certificate retrieval, providing valuable reconnaissance data without requiring manual script selection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use default scripts

    Why this is correct

    The -sC flag is shorthand for --script=default, which loads the default category of Nmap Scripting Engine (NSE) scripts. These scripts run automatically against open ports to enumerate service details, check for common misconfigurations, and report known vulnerabilities without sending aggressive payloads. The token 'sc' in the command corresponds to -sC, making this the correct interpretation of the intended option.

  • ✗

    Scan all ports

    Why it's wrong here

    Scanning all ports in Nmap is explicitly triggered with the -p- flag, which sets the port range to 1-65535 (or -p 1-65535). The command 'nmap sc sv' contains no -p flag or numeric port range, so it cannot perform an all-ports scan. Without any port specification, Nmap by default scans only the top 1000 most common ports, so this option is decisively wrong.

  • ✗

    Perform a version scan

    Why it's wrong here

    Service and version detection is performed by the -sV flag, which sends probes to open ports to identify the exact application and version (e.g., OpenSSH 8.9p1, Apache 2.4.41). Although the command contains the substring 'sv', it lacks the required leading dash and uses lowercase letters, so Nmap treats 'sv' as a hostname, not a version-scan option. Thus, the command as written does not invoke -sV and this choice is incorrect.

  • ✗

    Do a SYN scan

    Why it's wrong here

    A SYN scan (half-open scan) is selected with the -sS flag, a distinct option that sends SYN packets and analyzes responses without completing the TCP handshake; it is often the default scan type for privileged users. The command 'nmap sc sv' includes no -sS flag, and neither 'sc' nor 'sv' is recognized as a scan technique. Because the command does not request a SYN scan, this answer is wrong.

Go deeper

Related to this question

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.