PEN-200 › Enumeration and Reconnaissance
This domain covers active and passive information gathering before exploitation: host discovery, port and service scanning with Nmap, DNS and infrastructure enumeration, and interpreting scan responses correctly. PEN-200 tests it through scenario questions where you must choose the right scan type or tool and infer host state from ICMP, TCP, and RST/ACK behavior.
PEN-200 Enumeration and Reconnaissance — All 41 Questions
Every question in this domain with answers and detailed explanations.