PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is conducting active reconnaissance on a target network and wants to enumerate SNMP information. Which TWO of the following tools or commands can be used to query SNMP data from network devices? (Select TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
snmpwalk
snmpwalk is a standard SNMP tool to retrieve a subtree of MIB data, and nmap can be used with SNMP scripts to enumerate information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WPScan
Why it's wrong here
WPScan is a specialized vulnerability scanner tailored specifically to WordPress, enumerating installed themes, plugins, and known CVE exploits for those components. It communicates exclusively over HTTP/HTTPS and has no protocol support for SNMP, so it cannot query UDP port 161 or retrieve OIDs from network infrastructure. Consequently, running WPScan against a device that is not hosting WordPress would produce no useful SNMP data.
- ✓
snmpwalk
Why this is correct
snmpwalk is the canonical command-line utility for actively enumerating SNMP-enabled devices, sending a sequence of GETNEXT requests to traverse the entire Management Information Base (MIB) tree. By default, it uses the community string 'public' via SNMPv2c, and a successful walk quickly reveals system name, interfaces, contacts, and even process tables—data that is extremely valuable during active reconnaissance. Unlike generic scanners, snmpwalk specifically implements the SNMP protocol and is designed to extract the full OID hierarchy in one pass.
- ✓
nmap with snmp scripts
Why this is correct
nmap with SNMP scripts provides a complementary active reconnaissance approach, leveraging the Nmap Scripting Engine (NSE) to query specific OID branches. Scripts such as snmp-info, snmp-interfaces, snmp-processes, and snmp-brute can enumerate device details and even guess weak community strings with a built-in wordlist. While not as exhaustive as a full snmpwalk of the entire MIB tree, nmap scripts are useful for targeted enumeration and can be combined with other scanning logic in a single pass.
- ✗
dig
Why it's wrong here
dig (Domain Information Groper) is a DNS lookup utility that queries name servers on port 53 (TCP/UDP) for records like A, AAAA, MX, NS, and TXT, and it can also perform zone transfers. It has zero capability to communicate with the SNMP protocol, which uses UDP port 161 and expects OID-based GET/GETNEXT requests. Using dig against an SNMP-enabled switch or router would only attempt DNS queries and return NXDOMAIN or no answer, never device telemetry.
- ✗
tcpdump
Why it's wrong here
tcpdump is a packet capture tool that passively listens on a network interface and records raw frames, including SNMP traffic if it is present on the wire. However, it only observes traffic; it does not generate the GET/GETNEXT/GETBULK requests that constitute active SNMP reconnaissance. To actively interrogate a target's SNMP agent, a tester must send crafted requests using a tool like snmpwalk or nmap—tcpdump merely captures the responses, so it is not a query tool.
Go deeper
Related to this question
Learn chapter
Penetration Testing Tools
Key term
Active reconnaissance
Active reconnaissance is the process of directly interacting with a target system or network to gather information, often through scanning and probing.
Key term
Nmap
Nmap is a network scanning tool used to discover hosts, services, and operating systems on a computer network.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.