Courseiva
mediumMultiple Choice

PT0-002 Practice Question: Refer to the exhibit

Exhibit

Nmap scan report for 192.168.1.10
Host is up (0.0010s latency).
PORT     STATE SERVICE
22/tcp   open  ssh
80/tcp   open  http
445/tcp  open  microsoft-ds
3389/tcp open  ms-wbt-server

Nmap done: 1 IP address (1 host up) scanned in 10.00 seconds

Refer to the exhibit. A penetration tester performed an Nmap scan of a target server and received the above output. The tester recalls that one of these services is associated with a well-known remote code execution vulnerability that can be exploited without authentication. Which service is most likely vulnerable?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft-DS (port 445)

Microsoft-DS on port 445, because SMBv1 (the service typically exposed on TCP 445) is associated with the well-known, unauthenticated remote code execution vulnerability EternalBlue (MS17-010), which was exploited by WannaCry and NotPetya. An Nmap scan showing Microsoft-DS on 445 should immediately raise this concern, since exploitation requires no credentials and can yield SYSTEM-level code execution. HTTP on port 80 (A) may host web vulnerabilities, but it is not tied to a single well-known unauthenticated RCE in the way SMBv1 is. SSH on port 22 (B) is an encrypted remote-login service that requires authentication and is not associated with an unauthenticated RCE of this kind. ms-wbt-server on port 3389 (D) is RDP, which is normally protected by authentication and credentials, so it does not fit the 'without authentication' criterion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    HTTP (port 80)

    Why it's wrong here

    HTTP on port 80 alone carries no specific unauthenticated RCE; exploitation depends on the web application or server version behind it, which the scan does not reveal. HTTP is the right answer when the exhibit shows a vulnerable web stack, such as an outdated Apache or IIS banner, rather than a bare open port.

  • ✗

    SSH (port 22)

    Why it's wrong here

    SSH on port 22 is not associated with an unauthenticated RCE; OpenSSH's notable flaws, such as regreSSHion, require specific vulnerable versions and conditions absent from the exhibit. SSH is the correct focus when the scan reveals a known-vulnerable OpenSSH banner, not simply an exposed port 22.

  • ✓

    Microsoft-DS (port 445)

    Why this is correct

    Microsoft-DS on port 445 exposes SMB, historically vulnerable to unauthenticated remote code execution such as EternalBlue (MS17-010). That flaw lets an attacker execute code without credentials, matching the stem's requirement for a well-known no-authentication RCE service.

  • ✗

    ms-wbt-server (port 3389)

    Why it's wrong here

    ms-wbt-server is Microsoft's RDP endpoint; BlueKeep (CVE-2019-0708) is pre-auth RCE, but it affects only unpatched Windows 7/Server 2008 R2 systems, and the exhibit gives no version evidence. RDP is the correct target when a vulnerable legacy Windows host is confirmed, not merely when port 3389 is open.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.