mediumMultiple Choice
PT0-002 Practice Question: Refer to the exhibit
Exhibit
Nmap scan report for 192.168.1.10 Host is up (0.0010s latency). PORT STATE SERVICE 22/tcp open ssh 80/tcp open http 445/tcp open microsoft-ds 3389/tcp open ms-wbt-server Nmap done: 1 IP address (1 host up) scanned in 10.00 seconds
Refer to the exhibit. A penetration tester performed an Nmap scan of a target server and received the above output. The tester recalls that one of these services is associated with a well-known remote code execution vulnerability that can be exploited without authentication. Which service is most likely vulnerable?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft-DS (port 445)
Microsoft-DS on port 445, because SMBv1 (the service typically exposed on TCP 445) is associated with the well-known, unauthenticated remote code execution vulnerability EternalBlue (MS17-010), which was exploited by WannaCry and NotPetya. An Nmap scan showing Microsoft-DS on 445 should immediately raise this concern, since exploitation requires no credentials and can yield SYSTEM-level code execution. HTTP on port 80 (A) may host web vulnerabilities, but it is not tied to a single well-known unauthenticated RCE in the way SMBv1 is. SSH on port 22 (B) is an encrypted remote-login service that requires authentication and is not associated with an unauthenticated RCE of this kind. ms-wbt-server on port 3389 (D) is RDP, which is normally protected by authentication and credentials, so it does not fit the 'without authentication' criterion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
HTTP (port 80)
Why it's wrong here
HTTP on port 80 alone carries no specific unauthenticated RCE; exploitation depends on the web application or server version behind it, which the scan does not reveal. HTTP is the right answer when the exhibit shows a vulnerable web stack, such as an outdated Apache or IIS banner, rather than a bare open port.
- ✗
SSH (port 22)
Why it's wrong here
SSH on port 22 is not associated with an unauthenticated RCE; OpenSSH's notable flaws, such as regreSSHion, require specific vulnerable versions and conditions absent from the exhibit. SSH is the correct focus when the scan reveals a known-vulnerable OpenSSH banner, not simply an exposed port 22.
- ✓
Microsoft-DS (port 445)
Why this is correct
Microsoft-DS on port 445 exposes SMB, historically vulnerable to unauthenticated remote code execution such as EternalBlue (MS17-010). That flaw lets an attacker execute code without credentials, matching the stem's requirement for a well-known no-authentication RCE service.
- ✗
ms-wbt-server (port 3389)
Why it's wrong here
ms-wbt-server is Microsoft's RDP endpoint; BlueKeep (CVE-2019-0708) is pre-auth RCE, but it affects only unpatched Windows 7/Server 2008 R2 systems, and the exhibit gives no version evidence. RDP is the correct target when a vulnerable legacy Windows host is confirmed, not merely when port 3389 is open.
Go deeper
Related to this question
Learn chapter
Vulnerability Identification
Key term
Active reconnaissance
Active reconnaissance is the process of directly interacting with a target system or network to gather information, often through scanning and probing.
Key term
Nmap
Nmap is a network scanning tool used to discover hosts, services, and operating systems on a computer network.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.