Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

During a penetration test, the tester runs an Nmap scan with the -sV option and gets a result showing 'Apache httpd 2.4.49'. This version is known to be vulnerable to a path traversal attack. Which of the following best describes the next step the tester should take?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attempt to exploit the vulnerability using a known exploit.

After identifying a potentially vulnerable service, the tester should verify the vulnerability by attempting exploitation in a controlled manner to avoid false positives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ignore it because Nmap version detection is unreliable.

    Why it's wrong here

    Nmap's -sV version detection is a reliable industry-standard method, but no tool is infallible; if a version is uncertain, the correct action is to manually verify it using a direct connection, not dismiss it. Ignoring a potential vulnerability because of skepticism about Nmap's accuracy would leave an unverified finding that could be a real risk. The professional protocol is to validate the version with additional probing rather than discard the data, because service version details are critical to scope whether an exploit applies.

  • ✓

    Attempt to exploit the vulnerability using a known exploit.

    Why this is correct

    Attempting to exploit the identified vulnerability using a known, publicly available exploit (e.g., a Metasploit module or a PoC from Exploit-DB) is the definitive validation step in penetration testing. It transforms a potential false positive into demonstrated proof by showing that the service is actually vulnerable and the exploit path yields a controlled outcome. This must be executed with explicit authorization and caution, as a failed or unstable exploit could crash the target service, and the tester should gain approval for any exploit that may have a destructive impact. The successful execution provides concrete evidence, including command output and system access, that is far more persuasive to the client than a simple version-match.

  • ✗

    Report the vulnerability immediately.

    Why it's wrong here

    Reporting a vulnerability immediately after an Nmap scan is premature because version-based vulnerability detection is often inferred from banner strings, which can misrepresent the actual patch level due to backported fixes or custom builds. A penetration test report should only include confirmed findings, so the tester must first perform validation steps—such as manual verification or exploitation—to ensure the vulnerability is exploitable. Reporting unverified vulnerabilities can trigger unnecessary urgent actions by the client, erode the tester's credibility, and violate the testing methodology outlined in PT0-003. Therefore, immediate reporting is not the appropriate action; it should come after evidence is gathered.

  • ✗

    Move on to other targets since the vulnerability is well-known.

    Why it's wrong here

    Moving on to other targets simply because a vulnerability is well-known undermines the purpose of the penetration test, as every disclosed CVE must be validated against the specific target's configuration and mitigation status. The target might be managed by a compensating control, have a patched kernel, or run a different version despite the banner, so the vulnerability could be a false positive. Even if the exploit is well-documented, the tester is expected to confirm and document the finding as part of the deliverable, including noting that it is unpatched and what impact it could have. Therefore, the correct decision is to verify the vulnerability as it could be a critical finding for the environment, not to skip it.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.