exam questions

Exam PT0-002 All Questions

View all questions & answers for the PT0-002 exam

Exam PT0-002 topic 1 question 90 discussion

Actual exam question from CompTIA's PT0-002
Question #: 90
Topic #: 1
[All PT0-002 Questions]

An Nmap network scan has found five open ports with identified services. Which of the following tools should a penetration tester use NEXT to determine if any vulnerabilities with associated exploits exist on the open ports?

  • A. OpenVAS
  • B. Drozer
  • C. Burp Suite
  • D. OWASP ZAP
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
som3onenooned1
Highly Voted 1 year, 6 months ago
Selected Answer: A
OpenVAS is a full-featured vulnerability scanner. OWASP ZAP = Burp Suite Drozer (Android) = drozer allows you to search for security vulnerabilities in apps and devices by assuming the role of an app and interacting with the Dalvik VM, other apps' IPC endpoints and the underlying OS.
upvoted 7 times
...
RRabbit_111
Highly Voted 1 year, 3 months ago
A. OpenVAS OpenVAS (Open Vulnerability Assessment System) is a free and open-source vulnerability scanner that can be used to identify vulnerabilities on a network or system. It can scan for known vulnerabilities on open ports and services, and can also check for specific vulnerabilities based on the version of the software running on the target system. Once vulnerabilities are identified, OpenVAS can also provide information about potential exploits that could be used to exploit those vulnerabilities. After identifying the open ports and services with Nmap, the next step is to check if there are any known vulnerabilities on those open ports, OpenVAS is a suitable tool to do that. Other tools such as Drozer and Burp Suite, can be used for testing the security of Android and web applications respectively, but they are not suitable for vulnerability scanning. OWASP ZAP is also a web application security scanner, it can be used to find vulnerabilities on web applications, but it's not suitable for vulnerability scanning on ports.
upvoted 5 times
...
IYKMba
Most Recent 8 months, 2 weeks ago
Selected Answer: A
Openvas is the right tool
upvoted 1 times
...
Gargamella
1 year ago
The question is toking about network scan. So for me the right reponse is OpenVas
upvoted 1 times
...
nickwen007
1 year, 1 month ago
OpenVAS is an open source vulnerability scanner used to detect security weaknesses in computer networks. It is based on the Nessus scanning engine and uses a wide range of network and web security tests to quickly identify vulnerabilities, misconfigurations, and exposed credentials on systems.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago