Courseiva

PEN-200 Enumeration and Reconnaissance Practice Question

Exhibit

Starting Nmap 7.91 ( https://nmap.org ) at 2023-10-27 10:00 UTC
Nmap scan report for 192.168.1.10
Host is up (0.001s latency).
Not shown: 998 closed ports
PORT    STATE SERVICE
22/tcp  open  ssh
80/tcp  open  http

Refer to the exhibit. Which ports are currently open on the target host 192.168.1.10?

⚠ Common exam trap

Candidates often misread Nmap output columns, confusing filtered or closed ports with open ones, or missing secondary ports running non-standard services due to rushing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ports 22 and 80.

The Nmap output clearly indicates the state of the scanned ports. In this exhibit, ports 22 and 80 are explicitly listed as 'open', while 998 others are closed. Identifying these specific ports is the first step in mapping the target's attack surface. Understanding how to read scan output is a core competency that allows a tester to prioritize their focus towards the services that are most likely to be exploitable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    All ports from 1 to 1000.

    Why it's wrong here

    The output states that 998 ports are closed. Claiming all 1000 are open is a direct contradiction of the provided text. Accurate reading of scan results is non-negotiable, as misinterpreting data can lead to targeting services that are not actually present or available for interaction during the assessment.

  • ✗

    Only port 22.

    Why it's wrong here

    The output explicitly lists both port 22 and port 80 as open. Ignoring port 80 would be a major oversight, as web services are among the most common and critical entry points in an assessment, and failing to notice this would result in a significant gap in the reconnaissance process.

  • ✓

    Ports 22 and 80.

    Why this is correct

    The scan report explicitly shows that ports 22/tcp and 80/tcp are in the 'open' state. Correctly identifying these ports is fundamental to the reconnaissance phase, as it provides the necessary roadmap for deciding which service to analyze further for potential vulnerabilities or configuration weaknesses during the engagement.

  • ✗

    No ports are open.

    Why it's wrong here

    The report clearly displays two open ports. Stating that no ports are open ignores the provided data entirely, which would be a critical failure in an assessment scenario. Every detail in a scan report is vital for building an accurate picture of the target environment's security posture.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.