PT0-002 Vulnerability Discovery and Analysis Practice Question
During a penetration test, the tester wants to capture network traffic for later analysis. Which tool is most appropriate for capturing packets and saving them to a pcap file?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Wireshark
Wireshark is a network protocol analyzer capable of capturing live traffic and saving it to pcap files.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Wireshark
Why this is correct
Wireshark is a network protocol analyzer that captures live traffic by putting the network interface into promiscuous mode via libpcap (or Npcap on Windows) and decoding frames from the data-link layer through the application layer. It is the standard tool for raw packet capture because it passively observes all packets on a network segment, regardless of transport protocol (TCP/UDP) or application (HTTP, SSH, DNS, etc.). Its dissectors, filters, and follow-stream capability directly support analyzing captured traffic, making it the correct choice for this task.
- ✗
Metasploit
Why it's wrong here
Metasploit is an exploitation framework that provides payloads, exploits, and auxiliary modules for actively interacting with target systems, but it does not natively capture raw network packets. While Metasploit can integrate with tools like Nmap for scanning or use modules such as psexec to collect credentials, any packet capture would require loading an external utility like Wireshark or tcpdump. Its purpose is to secure a session or execute code, not to passively observe the wire, so it would not be used for capturing network traffic.
- ✗
Burp Suite
Why it's wrong here
Burp Suite is a web-application testing proxy that intercepts and manipulates HTTP/HTTPS traffic between a browser and a target server, but it only sees application-layer web requests and responses. It does not capture raw frames or non-HTTP protocols such as DNS, SSH, SMTP, or ARP, because it operates at the proxy level rather than the network interface level. Thus, while it logs web traffic, it is not a general-purpose packet capture tool and would miss most of the traffic on a network.
- ✗
Nmap
Why it's wrong here
Nmap is an active network scanner that sends crafted packets to discover open ports, hosts, and services, and it analyzes responses to infer fingerprints and vulnerabilities. It does not passively capture arbitrary network traffic; its --packet-trace option merely prints the packets it itself sends and receives for debugging, not a full capture of unrelated traffic. Since it generates its own probes rather than observing existing traffic, Nmap is inappropriate for capturing network packets in a passive analysis context.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.