Courseiva
mediumMultiple Choice

PT0-002 Service Version Detection (Nmap -sV) Practice Question

Exhibit

Refer to the exhibit.

Exhibit: NMAP scan output
```
PORT     STATE    SERVICE
22/tcp   open     ssh
80/tcp   open     http
443/tcp  open     https
8080/tcp open     http-proxy
```

Refer to the exhibit. A penetration tester performed an initial nmap scan and recorded the above output. The tester wants to include this in the report. What additional information should the tester add to make the finding more useful for remediation?

⚠ Common exam trap

The trap is assuming that OS detection or UDP scan results are more important, but remediation teams need service versions to map findings to known vulnerabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The version of services running on each port.

The correct option is A, the version of services running on each port, because knowing the exact service and version (e.g., Apache 2.4.49, OpenSSH 8.2p1) lets defenders map findings to known CVEs and apply targeted patches or upgrades. A raw nmap port list only shows TCP/UDP openness and cannot drive remediation without identifying the vulnerable software behind each port. Option B is insufficient because open ports alone do not reveal exploitable services. Option C, the OS of each host, is useful context but does not identify the vulnerable application layer. Option D, a UDP scan, expands coverage but still does not provide the service-version detail needed for remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The version of services running on each port.

    Why this is correct

    The version of services running on each port is the critical missing piece because the penetration tester has already identified open ports, but without knowing the exact software release (e.g., Apache 2.4.49 vs. 2.4.50), they cannot map those services to specific CVEs and exploit modules. Banner grabbing or Nmap's -sV flag would supply this data, directly enabling vulnerability research and exploitation planning.

  • ✗

    The list of open ports only.

    Why it's wrong here

    The list of open ports only is insufficient because ports alone identify a network service generically (e.g., TCP/443 is HTTPS), but the same port can host different software versions with vastly different security postures. The exhibit already enumerates which ports are open; the next step in a penetration test is to determine the service and version running on each, not to re-list the same ports.

  • ✗

    The operating system of each host.

    Why it's wrong here

    The operating system of each host is not the immediate missing information because the exhibit primarily shows port-level scan results, and OS detection (Nmap -O) is a separate enumeration technique that uses TCP/IP fingerprinting. While knowing the OS is useful later for tailoring exploits, it does not directly help identify vulnerabilities in the specific network services discovered, which are service-version dependent.

  • ✗

    The result of a UDP scan for these ports.

    Why it's wrong here

    The result of a UDP scan for these ports is outside the scope of the current exhibit because the question concerns information derivable from an initial TCP port scan or the data already presented. A UDP scan (e.g., Nmap -sU) would target different protocols like DNS (53/UDP) or SNMP (161/UDP), and while valuable, it is not the missing detail required to assess vulnerabilities in the already-listed TCP services.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.