Courseiva

PEN-200 Enumeration and Reconnaissance Practice Question

Which command-line tool is primarily used during the reconnaissance phase to identify open ports and service versions on a remote target?

⚠ Common exam trap

Candidates often confuse Nmap with vulnerability scanners like Nessus or OpenVAS. While Nmap can run scripts, its primary role is port scanning, service detection, and reconnaissance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Nmap

Nmap is the industry-standard tool for port scanning and service enumeration. By identifying open ports and the software versions running on them, a tester can pinpoint specific vulnerabilities to research. This step is the foundation of the reconnaissance phase, as it maps the target's attack surface and guides the subsequent selection of exploits, ensuring a focused and efficient penetration testing process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    netcat

    Why it's wrong here

    Netcat is a versatile networking utility often used for manual banner grabbing or simple data transfers. While it can connect to ports, it is not designed for efficient, large-scale port scanning or service version detection, which are better handled by dedicated scanners like Nmap in a professional assessment.

  • ✓

    Nmap

    Why this is correct

    Nmap is the primary utility for network discovery and security auditing. It offers advanced features like service version detection, operating system fingerprinting, and scriptable automation, making it the most reliable and comprehensive tool available for identifying the services running on a target during the reconnaissance phase of testing.

  • ✗

    Wireshark

    Why it's wrong here

    Wireshark is a packet analyzer used for inspecting network traffic in real-time. It is excellent for deep protocol analysis but is not a scanning tool designed to probe ports or identify remote service versions on a target host, making it unsuitable for the initial reconnaissance phase of an assessment.

  • ✗

    grep

    Why it's wrong here

    Grep is a command-line text search utility used to find patterns within files. It is purely for data processing and string manipulation and lacks any networking capabilities required for interacting with remote targets, identifying open ports, or performing the service enumeration necessary during the reconnaissance phase of testing.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.