Courseiva
easyMultiple Choice

PT0-002 Practice Question: A penetration tester wants to enumerate SMB…

A penetration tester wants to enumerate SMB shares, user lists, and operating system information from a Windows target without authenticating. Which of the following tools is BEST suited for this task?

⚠ Common exam trap

Many candidates confuse nmblookup or nbtscan as tools for SMB enumeration, but they only handle NetBIOS name resolution, not the deeper SMB share or user enumeration that enum4linux automates.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

enum4linux

enum4linux is a Perl wrapper around tools like smbclient, nmblookup, and nbtscan, specifically designed to extract SMB shares, user lists, and OS information from Windows targets without authentication by leveraging null sessions and SMB RPC calls (e.g., via MSRPC over SMB). It automates the enumeration of these details using the Server Message Block (SMB) protocol, making it the best choice for unauthenticated reconnaissance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    enum4linux

    Why this is correct

    enum4linux is a comprehensive Perl wrapper that automates null-session queries via rpcclient, net, and smbclient to extract a wide range of SMB/NetBIOS data, including user lists, share names, group memberships, password policies, and OS information. It is considered the go-to tool for unauthenticated enumeration of Windows and Samba targets because it consolidates dozens of RPC calls into one script, making it far more thorough than individual utilities.

  • ✗

    smbclient

    Why it's wrong here

    smbclient functions as an FTP-style client for SMB connections, requiring a valid share name and often valid credentials before it can list or transfer files. While the '-L' option can query a server for available shares, it does not extract users, groups, or detailed policy information, and it lacks the automated multi-protocol enumeration logic that a dedicated enumeration tool provides.

  • ✗

    nmblookup

    Why it's wrong here

    nmblookup specifically implements the NetBIOS Name Service (NBNS) protocol, sending UDP broadcast or directed queries to map a NetBIOS name to an IP address or to retrieve a node's name table. It has no capability to query SMB RPC endpoints, so it cannot retrieve user accounts or share listings; it merely performs name resolution, which is a precursor to SMB enumeration, not enumeration itself.

  • ✗

    nbtscan

    Why it's wrong here

    nbtscan is a dedicated NetBIOS scanner that sends NBNS queries to every host on a subnet and interprets the NetBIOS name table responses, which can reveal hostnames, logged-in usernames, and available share names if present in the names. However, it is a quick, single-pass reconnaissance tool that relies on the information already embedded in NetBIOS name records, and it does not actively query SMB RPC services like enum4linux does, so its output is shallow and often incomplete for a full user/share audit.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.