Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is performing a security assessment of a network that uses SNMP. The tester successfully connects to a device using the community string 'public'. Which tool would the tester MOST likely use to enumerate the entire Management Information Base (MIB) tree to extract system information, running processes, and network interfaces?

⚠ Common exam trap

A common mix-up: candidates confuse snmp-check with snmpwalk, assuming both perform the same MIB traversal, but snmp-check only queries a fixed set of OIDs while snmpwalk recursively retrieves the entire tree.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

snmpwalk

snmpwalk is the correct tool because it uses SNMP GETNEXT requests to systematically traverse the entire Management Information Base (MIB) tree, retrieving all OID values from a device. Given the tester already has a valid community string ('public'), snmpwalk can extract detailed system information, running processes, and network interfaces without needing to guess or brute-force credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    snmp-check

    Why it's wrong here

    snmp-check is an SNMP enumeration utility that gathers specific high-level information such as running processes, open UDP/TCP ports, user accounts, and installed software by sending a series of preset probes. However, it does not perform a full OID tree traversal, so it cannot expose every manageable object that snmpwalk can retrieve. In a security assessment where the goal is to dump the entire MIB, snmp-check is incomplete because it only queries a curated subset of OIDs.

  • ✗

    MIB Browser

    Why it's wrong here

    MIB Browser is a graphical SNMP management tool that provides a point-and-click interface for viewing and traversing MIB objects, making it less suitable for automated or headless penetration testing workflows. It is designed primarily for administrative tasks and interactive exploration rather than for scripting comprehensive MIB dumps. In a command-line-oriented assessment, using a GUI tool is impractical, and it does not offer the same efficiency or flexibility as snmpwalk for recursive enumeration of the entire MIB tree.

  • ✓

    snmpwalk

    Why this is correct

    snmpwalk is the standard command-line tool for walking the MIB tree, using SNMP GETNEXT and GETBULK operations to sequentially retrieve all OIDs in a subtree. It recursively enumerates every accessible managed object from the root (or a specified OID), making it the definitive tool for full SNMP information disclosure testing. When an assessment requires a complete snapshot of a device's SNMP-accessible data, snmpwalk is the correct and most comprehensive choice.

  • ✗

    Nmap with snmp-brute script

    Why it's wrong here

    Nmap's snmp-brute script is specifically designed to brute-force SNMP community strings by attempting a dictionary of common strings against the target. Even when it finds a valid community string, it does not perform an exhaustive MIB tree walk; instead, it typically reports the discovered string and perhaps basic system information. Thus, its purpose is credential discovery, not MIB enumeration, making it inappropriate for the task of dumping all MIB objects.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.