easyMultiple Choice
PT0-002 Practice Question: A tester is using the following Nmap command:…
A tester is using the following Nmap command: nmap -sC -sV -p 1-65535 target_ip. What is the primary purpose of the -sC option?
⚠ Common exam trap
Test-takers frequently confuse -sC with -sV or -sS, because all three options start with 's' and are commonly used together, but each has a distinct function that must be memorized for the exam.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use default scripts
The -sC option in Nmap is equivalent to --script=default, which runs a collection of common, non-intrusive enumeration scripts against the target. These scripts perform tasks such as service banner grabbing, HTTP title extraction, and SSL/TLS certificate retrieval, providing valuable reconnaissance data without requiring manual script selection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use default scripts
Why this is correct
The -sC flag is shorthand for --script=default, which loads the default category of Nmap Scripting Engine (NSE) scripts. These scripts run automatically against open ports to enumerate service details, check for common misconfigurations, and report known vulnerabilities without sending aggressive payloads. The token 'sc' in the command corresponds to -sC, making this the correct interpretation of the intended option.
- ✗
Scan all ports
Why it's wrong here
Scanning all ports in Nmap is explicitly triggered with the -p- flag, which sets the port range to 1-65535 (or -p 1-65535). The command 'nmap sc sv' contains no -p flag or numeric port range, so it cannot perform an all-ports scan. Without any port specification, Nmap by default scans only the top 1000 most common ports, so this option is decisively wrong.
- ✗
Perform a version scan
Why it's wrong here
Service and version detection is performed by the -sV flag, which sends probes to open ports to identify the exact application and version (e.g., OpenSSH 8.9p1, Apache 2.4.41). Although the command contains the substring 'sv', it lacks the required leading dash and uses lowercase letters, so Nmap treats 'sv' as a hostname, not a version-scan option. Thus, the command as written does not invoke -sV and this choice is incorrect.
- ✗
Do a SYN scan
Why it's wrong here
A SYN scan (half-open scan) is selected with the -sS flag, a distinct option that sends SYN packets and analyzes responses without completing the TCP handshake; it is often the default scan type for privileged users. The command 'nmap sc sv' includes no -sS flag, and neither 'sc' nor 'sv' is recognized as a scan technique. Because the command does not request a SYN scan, this answer is wrong.
Go deeper
Related to this question
Learn chapter
SMB Enumeration with enum4linux and CrackMapExec
Key term
Enumeration
Enumeration is the systematic process of extracting detailed information about a target system, such as user accounts, network shares, services, and configurations, used during the reconnaissance phase of a security assessment.
Key term
Banner grabbing
Banner grabbing is the process of connecting to a remote service to capture the banner it sends, which often reveals software type and version for reconnaissance.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.