PEN-200 Enumeration and Reconnaissance Practice Question
Exhibit
Starting Nmap 7.91 ( https://nmap.org ) at 2023-10-27 10:00 UTC Nmap scan report for 192.168.1.10 Host is up (0.001s latency). Not shown: 998 closed ports PORT STATE SERVICE 22/tcp open ssh 80/tcp open http
Refer to the exhibit. Which ports are currently open on the target host 192.168.1.10?
⚠ Common exam trap
Candidates often misread Nmap output columns, confusing filtered or closed ports with open ones, or missing secondary ports running non-standard services due to rushing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ports 22 and 80.
The Nmap output clearly indicates the state of the scanned ports. In this exhibit, ports 22 and 80 are explicitly listed as 'open', while 998 others are closed. Identifying these specific ports is the first step in mapping the target's attack surface. Understanding how to read scan output is a core competency that allows a tester to prioritize their focus towards the services that are most likely to be exploitable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All ports from 1 to 1000.
Why it's wrong here
The output states that 998 ports are closed. Claiming all 1000 are open is a direct contradiction of the provided text. Accurate reading of scan results is non-negotiable, as misinterpreting data can lead to targeting services that are not actually present or available for interaction during the assessment.
- ✗
Only port 22.
Why it's wrong here
The output explicitly lists both port 22 and port 80 as open. Ignoring port 80 would be a major oversight, as web services are among the most common and critical entry points in an assessment, and failing to notice this would result in a significant gap in the reconnaissance process.
- ✓
Ports 22 and 80.
Why this is correct
The scan report explicitly shows that ports 22/tcp and 80/tcp are in the 'open' state. Correctly identifying these ports is fundamental to the reconnaissance phase, as it provides the necessary roadmap for deciding which service to analyze further for potential vulnerabilities or configuration weaknesses during the engagement.
- ✗
No ports are open.
Why it's wrong here
The report clearly displays two open ports. Stating that no ports are open ignores the provided data entirely, which would be a critical failure in an assessment scenario. Every detail in a scan report is vital for building an accurate picture of the target environment's security posture.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.