Which of the following commands is used to enumerate SNMP information from a network device using a specific community string?
snmpwalk is the correct and standard command-line utility for enumerating SNMP (Simple Network Management Protocol) information from a target device. The `-c public` option specifies the community string, which acts as a password for accessing SNMP data, with "public" being a common default. The `-v 2c` flag designates SNMP version 2c, a widely supported version, while `192.168.1.1` is the target IP address from which to retrieve Management Information Base (MIB) data. This command systematically queries the entire MIB tree, revealing device configurations, network statistics, and system details.
Why this answer
`snmpwalk` is the standard command-line tool for enumerating SNMP (Simple Network Management Protocol) information from a network device. By specifying the community string (`-c public`) and SNMP version (`-v 2c`), it retrieves the entire Management Information Base (MIB) tree from the target IP address, allowing an attacker to discover system details, running processes, and network interfaces.
Exam trap
The trap here is that candidates confuse SNMP enumeration tools with other network enumeration tools (like LDAP, SMB, or NetBIOS), leading them to pick a command that targets a different protocol entirely.
How to eliminate wrong answers
Option A is wrong because `ldapsearch` is used for querying LDAP directories (port 389), not for SNMP enumeration; it requires a base DN and is unrelated to community strings. Option B is wrong because `enum4linux` is a tool for enumerating SMB/CIFS shares, users, and policies from Windows systems (port 445), not for SNMP queries. Option D is wrong because `nbtstat` is a Windows utility for NetBIOS over TCP/IP name resolution and cache management (port 137), not for SNMP enumeration.