PT0-002 Reconnaissance and Enumeration Practice Question
During a penetration test, you want to perform a stealthy port scan that minimizes the chance of being logged by the target. Which Nmap option should you use?
⚠ Common exam trap
PT0-003 often tests the misconception that any scan without a full handshake is undetectable; candidates may pick -sT thinking it is stealthy because it is the default for unprivileged users, but it is actually the most logged scan type.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
-sS
The -sS option performs a TCP SYN scan (half-open scan), which sends SYN packets and never completes the TCP handshake. Because the connection is never fully established, the target's application layer never logs the connection, making it the stealthiest common scan type. It requires raw socket privileges (root/admin) but is the default scan type when Nmap is run with elevated privileges.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
-sU
Why it's wrong here
-sU performs UDP scanning, which is slow and often elicits ICMP port-unreachable replies that targets readily log. It is tempting for finding DNS, SNMP or DHCP services, where UDP coverage is genuinely required, but it does not reduce logging for a stealthy scan.
- ✗
-sV
Why it's wrong here
-sV probes open ports to identify service versions, generating extra traffic that targets and IDS readily log. It is tempting because banner and version data aid exploitation, and it is correct when fingerprinting services, but it adds noise rather than minimising detection.
- ✗
-sT
Why it's wrong here
-sT completes the full TCP three-way handshake via the OS, so the service logs each connection. It is tempting because it needs no raw-socket privileges, making it correct for unprivileged users, but it is the least stealthy scan type available.
- ✓
-sS
Why this is correct
The -sS TCP SYN half-open scan sends a SYN, reads the SYN-ACK, then tears down with RST before the connection completes. Because no session is established, most application and host logging never records it, satisfying the stem's stealth requirement.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.