easyMultiple Choice
PT0-002 Practice Question: A penetration tester wants to enumerate SMB…
A penetration tester wants to enumerate SMB shares, user lists, and operating system information from a Windows target without authenticating. Which of the following tools is BEST suited for this task?
⚠ Common exam trap
Many candidates confuse nmblookup or nbtscan as tools for SMB enumeration, but they only handle NetBIOS name resolution, not the deeper SMB share or user enumeration that enum4linux automates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
enum4linux
enum4linux is a Perl wrapper around tools like smbclient, nmblookup, and nbtscan, specifically designed to extract SMB shares, user lists, and OS information from Windows targets without authentication by leveraging null sessions and SMB RPC calls (e.g., via MSRPC over SMB). It automates the enumeration of these details using the Server Message Block (SMB) protocol, making it the best choice for unauthenticated reconnaissance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
enum4linux
Why this is correct
enum4linux is a comprehensive Perl wrapper that automates null-session queries via rpcclient, net, and smbclient to extract a wide range of SMB/NetBIOS data, including user lists, share names, group memberships, password policies, and OS information. It is considered the go-to tool for unauthenticated enumeration of Windows and Samba targets because it consolidates dozens of RPC calls into one script, making it far more thorough than individual utilities.
- ✗
smbclient
Why it's wrong here
smbclient functions as an FTP-style client for SMB connections, requiring a valid share name and often valid credentials before it can list or transfer files. While the '-L' option can query a server for available shares, it does not extract users, groups, or detailed policy information, and it lacks the automated multi-protocol enumeration logic that a dedicated enumeration tool provides.
- ✗
nmblookup
Why it's wrong here
nmblookup specifically implements the NetBIOS Name Service (NBNS) protocol, sending UDP broadcast or directed queries to map a NetBIOS name to an IP address or to retrieve a node's name table. It has no capability to query SMB RPC endpoints, so it cannot retrieve user accounts or share listings; it merely performs name resolution, which is a precursor to SMB enumeration, not enumeration itself.
- ✗
nbtscan
Why it's wrong here
nbtscan is a dedicated NetBIOS scanner that sends NBNS queries to every host on a subnet and interprets the NetBIOS name table responses, which can reveal hostnames, logged-in usernames, and available share names if present in the names. However, it is a quick, single-pass reconnaissance tool that relies on the information already embedded in NetBIOS name records, and it does not actively query SMB RPC services like enum4linux does, so its output is shallow and often incomplete for a full user/share audit.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.