mediumMultiple Choice
PT0-002 Practice Question: During a vulnerability scan, a penetration tester…
During a vulnerability scan, a penetration tester notices that the scanner is repeatedly attempting to exploit a service, causing the service to crash and generating misleading findings. Which of the following scan configurations would BEST help the tester avoid this issue while still identifying potential vulnerabilities?
⚠ Common exam trap
Many exam-takers confuse scan rate adjustments (timing templates) or stealth techniques (SYN scan) with the ability to prevent service disruption, when in fact only disabling intrusive checks directly addresses the crashing issue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Activate the 'safe checks' option in the scanner
The 'safe checks' option in vulnerability scanners (such as Nessus or OpenVAS) disables intrusive plug-ins that attempt to exploit services aggressively, which can cause service crashes. This configuration allows the scanner to identify potential vulnerabilities without disrupting the target service, avoiding misleading findings from crashed services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable SYN scan instead of full TCP connect scan
Why it's wrong here
Enabling a SYN (half-open) scan alters the TCP handshake method used for port discovery, minimizing the number of fully established connections and logs left on the target. However, this choice only affects how ports are identified; once a port is discovered, the vulnerability scanner's plugin engine will still run the same suite of service-detection and exploit-testing plugins. The aggressiveness of those plugins is governed by separate options (such as 'safe checks'), not by the underlying port-scan technique.
- ✗
Adjust the scan timing template to a slower rate
Why it's wrong here
Adjusting the scan timing template to a slower rate (for example, T1 or T2) reduces packet transmission speed, connection parallelism, and overall network load, which can help avoid overwhelming the target or tripping intrusion detection systems. That said, timing templates only control the scanner's bandwidth and pacing; they do not in any way alter the set of vulnerability checks that will be executed against open services. Even a deliberately slow scan will still attempt the same potentially intrusive exploit plugins that could disrupt a service, so this does nothing to make the scan safer.
- ✓
Activate the 'safe checks' option in the scanner
Why this is correct
Activating the 'safe checks' option is the correct solution because it instructs the scanner to suppress all plugins that are flagged as intrusive, disruptive, or destructive, and instead rely on non-invasive methods such as banner grabbing, version fingerprinting, and configuration analysis. This prevents the scanner from actively attempting to exploit a vulnerability to confirm its existence, thereby avoiding service crashes, data corruption, or other unintended side effects. It also reduces false positives that can arise from failed exploit attempts, making the scan results more reliable in a production environment.
- ✗
Increase the port range to include high ports
Why it's wrong here
Increasing the port range to include high ports broadens the scope of the scan by telling the scanner to probe more TCP/UDP port numbers, which might reveal web interfaces on 8080, management consoles on 8443, or other high-port services. However, this change simply expands which ports are checked; it has no effect on the scanner's testing policy or the plugins that will be executed against those discovered services. If the scanner's plugin set contains dangerous checks, those will still be fired at any newly found open port, so this option does not reduce the aggressiveness of the scan.
Go deeper
Related to this question
Learn chapter
Python for Penetration Testing
Key term
Nessus
Nessus is a vulnerability scanner that automatically identifies security weaknesses, missing patches, and misconfigurations in computer systems and networks.
Key term
OpenVAS
OpenVAS is an open-source vulnerability scanner that helps IT professionals identify security weaknesses in networks, systems, and applications.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.