During a penetration test, you need to enumerate SNMP information from network devices. Which of the following tools or commands can be used for SNMP enumeration? (Select TWO.)
Trap 1: nmap -sU
nmap -sU is a generic UDP port scanner that probes port 161 to determine whether UDP SNMP is open or filtered, but it does not decode or retrieve OID-based management values. While nmap can combine -sU with SNMP-specific NSE scripts (e.g., snmp-info) for deeper analysis, the bare -sU scan itself remains a connectivity test, not a full SNMP enumeration tool.
Trap 2: curl
curl is designed for HTTP, FTP, and other application-layer protocols that operate over TCP or clear-text streams, but SNMP uses the connectionless UDP transport with ASN.1 BER-encoded PDUs on port 161. Since curl has no built-in SNMP protocol support and cannot speak SNMP's request/response format, it is wholly unable to query an SNMP agent for management information.
Trap 3: snmp-check
snmp-check is a Perl-based utility that attempts default community strings and parses specific OIDs to display users, processes, and network interfaces, but it is not among the two standard tools expected for this task. It requires a valid community string upfront and lacks the brute-force capability of onesixtyone and the comprehensive MIB-walking power of snmpwalk, making it an ancillary script rather than a primary enumeration method.
- A
snmpwalk
snmpwalk is the definitive SNMP enumeration tool: it sends a sequence of GETNEXT requests to an Agent, iterating through the entire MIB tree and returning every OID value from a specified subtree. This exposes system information, running processes, interface details, and installed software, which is exactly what 'enumerating SNMP information' means in a penetration test.
- B
nmap -sU
Why it fails: nmap -sU is a generic UDP port scanner that probes port 161 to determine whether UDP SNMP is open or filtered, but it does not decode or retrieve OID-based management values. While nmap can combine -sU with SNMP-specific NSE scripts (e.g., snmp-info) for deeper analysis, the bare -sU scan itself remains a connectivity test, not a full SNMP enumeration tool.
- C
onesixtyone
onesixtyone is a dedicated SNMP community string brute-forcer: it fires a single GETNEXT request at UDP 161 using a wordlist of community strings, and any reply identifies a valid read community. This is an essential early step in SNMP enumeration because without a correct community string, tools like snmpwalk cannot authenticate; as a result it is one of the two canonical SNMP enumeration utilities.
- D
curl
Why it fails: curl is designed for HTTP, FTP, and other application-layer protocols that operate over TCP or clear-text streams, but SNMP uses the connectionless UDP transport with ASN.1 BER-encoded PDUs on port 161. Since curl has no built-in SNMP protocol support and cannot speak SNMP's request/response format, it is wholly unable to query an SNMP agent for management information.
- E
snmp-check
Why it fails: snmp-check is a Perl-based utility that attempts default community strings and parses specific OIDs to display users, processes, and network interfaces, but it is not among the two standard tools expected for this task. It requires a valid community string upfront and lacks the brute-force capability of onesixtyone and the comprehensive MIB-walking power of snmpwalk, making it an ancillary script rather than a primary enumeration method.