mediumMultiple Choice
PT0-002 Service Version Detection (Nmap -sV) Practice Question
Exhibit
Refer to the exhibit. Exhibit: NMAP scan output ``` PORT STATE SERVICE 22/tcp open ssh 80/tcp open http 443/tcp open https 8080/tcp open http-proxy ```
Refer to the exhibit. A penetration tester performed an initial nmap scan and recorded the above output. The tester wants to include this in the report. What additional information should the tester add to make the finding more useful for remediation?
⚠ Common exam trap
The trap is assuming that OS detection or UDP scan results are more important, but remediation teams need service versions to map findings to known vulnerabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The version of services running on each port.
The correct option is A, the version of services running on each port, because knowing the exact service and version (e.g., Apache 2.4.49, OpenSSH 8.2p1) lets defenders map findings to known CVEs and apply targeted patches or upgrades. A raw nmap port list only shows TCP/UDP openness and cannot drive remediation without identifying the vulnerable software behind each port. Option B is insufficient because open ports alone do not reveal exploitable services. Option C, the OS of each host, is useful context but does not identify the vulnerable application layer. Option D, a UDP scan, expands coverage but still does not provide the service-version detail needed for remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The version of services running on each port.
Why this is correct
The version of services running on each port is the critical missing piece because the penetration tester has already identified open ports, but without knowing the exact software release (e.g., Apache 2.4.49 vs. 2.4.50), they cannot map those services to specific CVEs and exploit modules. Banner grabbing or Nmap's -sV flag would supply this data, directly enabling vulnerability research and exploitation planning.
- ✗
The list of open ports only.
Why it's wrong here
The list of open ports only is insufficient because ports alone identify a network service generically (e.g., TCP/443 is HTTPS), but the same port can host different software versions with vastly different security postures. The exhibit already enumerates which ports are open; the next step in a penetration test is to determine the service and version running on each, not to re-list the same ports.
- ✗
The operating system of each host.
Why it's wrong here
The operating system of each host is not the immediate missing information because the exhibit primarily shows port-level scan results, and OS detection (Nmap -O) is a separate enumeration technique that uses TCP/IP fingerprinting. While knowing the OS is useful later for tailoring exploits, it does not directly help identify vulnerabilities in the specific network services discovered, which are service-version dependent.
- ✗
The result of a UDP scan for these ports.
Why it's wrong here
The result of a UDP scan for these ports is outside the scope of the current exhibit because the question concerns information derivable from an initial TCP port scan or the data already presented. A UDP scan (e.g., Nmap -sU) would target different protocols like DNS (53/UDP) or SNMP (161/UDP), and while valuable, it is not the missing detail required to assess vulnerabilities in the already-listed TCP services.
Go deeper
Related to this question
Learn chapter
Python for Penetration Testing
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
Key term
Nmap
Nmap is a network scanning tool used to discover hosts, services, and operating systems on a computer network.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.