What you seem to be suggesting -- a brute-force approach to discovering a server process -- can also be interpreted by a network monitoring agent as a prelude to a spam attack, so if you're thinking of doing this in a shared subnet, large LAN envirnoment, or on an ISP's network, be careful.
The SCEA has the EJB 1.0 in its target. So in my opinion, this
certification is totally useless without integrating EJB2.0
Hopefully soon we will see the new SCEA for J2EE 1.4, and then your concerns will be addressed.