CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisEasy
A penetration tester wants to run Nmap using the Nmap Scripting Engine to check open ports for known, publicly disclosed vulnerabilities. Which script category should the tester specify with the --script option?
- Asafe
- Bauth
- Cdiscovery
- Dvuln
Show answer & explanationAnswer & explanation
Correct answer: D. vuln
The 'vuln' NSE category contains scripts specifically designed to check targets for known vulnerabilities (e.g., --script vuln). 'discovery' finds hosts/services, 'safe' scripts are non-intrusive by design regardless of purpose, and 'auth' tests for authentication bypass, not general vulnerability detection.
Why the other options are wrong
- A. Safe scripts are a safety classification, not a vulnerability-detection category.
- B. Auth scripts test authentication mechanisms, a narrower purpose.
- C. Discovery scripts enumerate hosts and services, not vulnerabilities.
Nmap Scripting Engine (NSE) Categories
NSE scripts are grouped into categories that describe their purpose and intrusiveness, allowing testers to run targeted script sets with --script <category>.
- --script vuln targets known vulnerabilities
- --script safe scripts won't crash or disrupt services
- --script default runs a curated balanced set
Memory trick: 'Very Dangerous Scripts Are Vulnerable' - Default, Discovery, Safe, Auth, Vuln