CEH Enumeration and System Hacking Practice Question
Which TWO tools are commonly used for enumerating NFS exports on a target system? (Select 2 correct answers)
⚠ Common exam trap
Many candidates confuse SMB enumeration tools (like enum4linux or smbclient) with NFS enumeration tools, because both involve file sharing, but they operate on entirely different protocols (SMB vs. NFS/RPC) and require distinct command sets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
nmap (with script nfs-ls)
Option B, nmap with the nfs-ls script, is correct because Nmap's NSE script nfs-ls queries an NFS server and lists the files and directories available through its exports, making it a valid enumeration tool for NFS. Option D, showmount, is correct because showmount -e <target> directly queries the target's mountd/rpcbind service and displays the list of exported file systems, which is the classic NFS enumeration command. The other options do not belong: enum4linux (A) and smbclient (C) target SMB/NetBIOS/Windows shares rather than NFS, and ldapsearch (E) queries LDAP directory services, not NFS exports.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
enum4linux
Why it's wrong here
enum4linux is a powerful wrapper script designed specifically for enumerating information from Windows and Samba hosts. It leverages tools like rpcclient, net, and nmblookup to extract details such as user lists, group memberships, and shared resources (SMB shares). Consequently, it lacks the functionality to interact with or enumerate Network File System (NFS) exports, making it irrelevant for this task.
- ✓
nmap (with script nfs-ls)
Why this is correct
Nmap, a versatile network scanner, can be extended with its powerful Nmap Scripting Engine (NSE) to perform various enumeration tasks. The nfs-ls script, along with others like nfs-showmount and nfs-statfs, is specifically designed to interact with NFS services. It attempts to list exported directories and their permissions by querying the mount daemon (port 111) and the NFS server directly, providing detailed insights into available NFS shares.
- ✗
smbclient
Why it's wrong here
smbclient is a command-line utility specifically engineered to interact with Server Message Block (SMB) and Common Internet File System (CIFS) network shares. It functions as an SMB client, allowing users to browse, upload, and download files from Windows or Samba servers. Since NFS operates on a completely different protocol stack and port (typically UDP/TCP 2049), smbclient lacks the necessary protocol implementation to communicate with or enumerate NFS exports.
- ✓
showmount
Why this is correct
showmount is a standard Unix/Linux utility specifically designed for querying the mount daemon on an NFS server. Its primary function is to display information about the NFS server's exported directories and the clients that have mounted them. By executing showmount -e <target_IP>, an attacker can directly request a list of all currently exported file systems, making it a fundamental and highly effective tool for NFS enumeration.
- ✗
ldapsearch
Why it's wrong here
ldapsearch is a command-line utility used for querying and displaying information from Lightweight Directory Access Protocol (LDAP) directories. It facilitates searching for entries, attributes, and values stored within an LDAP server, which typically manages user accounts, group policies, and network resources. As LDAP is a directory service protocol entirely distinct from network file sharing protocols like NFS, ldapsearch possesses no capability to enumerate NFS exports.
Go deeper
Related to this question
Learn chapter
System Hacking
Key term
Port Scanning Techniques
Port scanning techniques are methods used to probe a computer or network to discover which network ports are open and which services are running on those ports.
Key term
LDAP Enumeration
LDAP Enumeration is the process of querying a Lightweight Directory Access Protocol server to gather information about users, groups, computers, and other network resources in an organization.
About these practice questions
Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.