Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is conducting active reconnaissance on a target network and wants to enumerate SNMP information. Which TWO of the following tools or commands can be used to query SNMP data from network devices? (Select TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

snmpwalk

snmpwalk is a standard SNMP tool to retrieve a subtree of MIB data, and nmap can be used with SNMP scripts to enumerate information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    WPScan

    Why it's wrong here

    WPScan is a specialized vulnerability scanner tailored specifically to WordPress, enumerating installed themes, plugins, and known CVE exploits for those components. It communicates exclusively over HTTP/HTTPS and has no protocol support for SNMP, so it cannot query UDP port 161 or retrieve OIDs from network infrastructure. Consequently, running WPScan against a device that is not hosting WordPress would produce no useful SNMP data.

  • ✓

    snmpwalk

    Why this is correct

    snmpwalk is the canonical command-line utility for actively enumerating SNMP-enabled devices, sending a sequence of GETNEXT requests to traverse the entire Management Information Base (MIB) tree. By default, it uses the community string 'public' via SNMPv2c, and a successful walk quickly reveals system name, interfaces, contacts, and even process tables—data that is extremely valuable during active reconnaissance. Unlike generic scanners, snmpwalk specifically implements the SNMP protocol and is designed to extract the full OID hierarchy in one pass.

  • ✓

    nmap with snmp scripts

    Why this is correct

    nmap with SNMP scripts provides a complementary active reconnaissance approach, leveraging the Nmap Scripting Engine (NSE) to query specific OID branches. Scripts such as snmp-info, snmp-interfaces, snmp-processes, and snmp-brute can enumerate device details and even guess weak community strings with a built-in wordlist. While not as exhaustive as a full snmpwalk of the entire MIB tree, nmap scripts are useful for targeted enumeration and can be combined with other scanning logic in a single pass.

  • ✗

    dig

    Why it's wrong here

    dig (Domain Information Groper) is a DNS lookup utility that queries name servers on port 53 (TCP/UDP) for records like A, AAAA, MX, NS, and TXT, and it can also perform zone transfers. It has zero capability to communicate with the SNMP protocol, which uses UDP port 161 and expects OID-based GET/GETNEXT requests. Using dig against an SNMP-enabled switch or router would only attempt DNS queries and return NXDOMAIN or no answer, never device telemetry.

  • ✗

    tcpdump

    Why it's wrong here

    tcpdump is a packet capture tool that passively listens on a network interface and records raw frames, including SNMP traffic if it is present on the wire. However, it only observes traffic; it does not generate the GET/GETNEXT/GETBULK requests that constitute active SNMP reconnaissance. To actively interrogate a target's SNMP agent, a tester must send crafted requests using a tool like snmpwalk or nmap—tcpdump merely captures the responses, so it is not a query tool.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.