PEN-200 · domain
Enumeration and Reconnaissance
This domain covers active and passive information gathering before exploitation: host discovery, port and service scanning with Nmap, DNS and infrastructure enumeration, and interpreting scan responses correctly. PEN-200 tests it through scenario questions where you must choose the right scan type or tool and infer host state from ICMP, TCP, and RST/ACK behavior.
Focused practice
Practice Enumeration and Reconnaissance questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Enumeration and Reconnaissance
You must be able to run and read Nmap scans, interpret ICMP and TCP responses, and enumerate DNS and services to build a target picture. The single most important skill is correctly distinguishing open, closed, and filtered states and what each reveals about the target's firewall and host status.
Interpreting Nmap port states (open, closed, filtered) and what each implies about firewalls
Enumerating DNS records (A, MX, NS, TXT) and mapping mail or name infrastructure
Using Nmap service/version detection and tools like nslookup, dig, and whois
Watch out for
Common Enumeration and Reconnaissance exam traps
Question index
All Enumeration and Reconnaissance questions (33)
Click any question to see the full explanation, or start a practice session above.
During enumeration you discover a DNS server that allows zone transfers to any client. What is the most valuable outcome of performing a successful AXFR against this server?
Hard2You are performing reconnaissance and want to identify if a target website uses a specific CMS like WordPress. What is the most effective approach?
Medium3Refer to the exhibit. You have scanned a target and obtained these results. Which step is most logical to perform next to effectively enumerate the web service?
Medium4You are enumerating a Linux host and discover TCP port 2049 open. You need to determine what is being exported and to whom before deciding on any exploitation path. Which action most directly answers that question?
Medium5Which THREE of the following are considered 'active' reconnaissance techniques, as opposed to passive techniques?
Hard6Which TWO of the following techniques are most effective for enumerating SMB shares on a Windows host during a penetration test?
Medium7During an external penetration test, you discover a web server hosting multiple virtual hosts. You want to enumerate additional hostnames that resolve to the same IP address without triggering intrusion detection systems. Which technique is most appropriate?
Hard8During an internal penetration test, you have captured network traffic and identified a host that responds on TCP port 445. You want to gather detailed information about the SMB service, including the operating system version, NetBIOS name, and domain, without authenticating. Which Nmap NSE script is most appropriate for this task?
Medium9You are performing web enumeration against a target application and want to discover hidden directories, backup files, and administrative interfaces that are not linked from the visible pages. Which two approaches are most appropriate for this goal? (Choose two.)
Medium10During an internal assessment you receive a scope that lists a /24 subnet but explicitly forbids any traffic that could cause service disruption. You need to identify live hosts and open TCP ports while keeping the scan as quiet and non-intrusive as possible. Which single Nmap invocation best matches these constraints?
Hard11When performing reconnaissance on an unknown network, you discover a service running on port 161. What is the most appropriate action to take to determine if this service can be abused?
Hard12You are enumerating a Linux host and find that UDP port 161 responds to SNMP queries with the community string 'public'. Which action yields the most useful reconnaissance data for planning later exploitation?
Hard13You are performing a network scan on a client segment and notice that a host responds to ICMP echo requests but shows all TCP ports as 'filtered' when using Nmap. Which conclusion is most accurate?
Medium14You are enumerating a Linux target and discover that TCP port 2049 is open. You run `showmount -e 192.168.1.100` and see that the `/home` directory is exported to everyone. What is the most significant security risk this configuration presents?
Medium15You are performing active reconnaissance against a web server and want to identify hidden directories and files that may not be linked from the main site. Which two techniques are most appropriate for this goal? (Choose two.)
Hard16Refer to the exhibit. Based on the HTTP response headers provided, what critical information can be gathered for your reconnaissance?
Medium17You have successfully identified a Windows target and need to perform deep enumeration. Which TWO techniques are most effective for identifying hidden local services and internal network connections?
Medium18You are conducting a penetration test and need to identify the operating system of a target host without sending any packets to it. Which of the following methods is most appropriate?
Easy19During an internal penetration test, you run a UDP scan against a Linux server and see the following result: `161/udp open snmp`. You want to extract as much host information as possible without triggering authentication failures. Which command should you run first?
Medium20During a network assessment, you want to enumerate users on a domain controller. Which protocol and port combination is the most standard target for this type of enumeration?
Medium21Which TWO of the following actions are considered best practice during the initial host enumeration phase to avoid detection by security monitoring tools?
Medium22When enumerating a web application, which THREE of the following items are most important to identify to increase the likelihood of finding a vulnerability?
Hard23Refer to the exhibit. Which ports are currently open on the target host 192.168.1.10?
Easy24While mapping a subnet you want to discover live hosts quickly before running detailed service scans. Which approach best fits an initial host-discovery sweep?
Easy25During external reconnaissance you collect DNS records for a target organization and find an MX record pointing to mail.example.com. You want to identify the IP addresses of other hosts in the same mail infrastructure without sending any packets directly to the target's servers. Which action best fits this passive goal?
Easy26During an internal assessment you run a TCP SYN scan and note that a host responds with an RST/ACK for every probed port. What does this behavior most reliably indicate about the target host?
Medium27Which command-line tool is primarily used during the reconnaissance phase to identify open ports and service versions on a remote target?
Easy28During a penetration test, you need to enumerate DNS records for the domain `example.com` to find subdomains and mail servers. Which command should you use to perform a zone transfer attempt?
Easy29You are performing a network scan on a target network and notice that ICMP echo requests are blocked, but you need to determine if the target host is alive. Which technique should you utilize to identify active hosts without relying on standard ICMP ping?
Medium30You have identified an open port 445 on a Windows machine. Which tool is most effective for checking if the machine is vulnerable to common SMB-based exploits like EternalBlue?
Medium31You need to fingerprint the web server technology behind an HTTP service without sending malformed or intrusive requests. Which two actions best accomplish passive-leaning banner and behavior fingerprinting during enumeration? (Choose two.)
Medium32You are enumerating an Apache web server and discover the '.git' directory is accessible. What is the most significant risk this poses for your reconnaissance?
Medium33You are enumerating a Windows host and have obtained valid low-privilege domain credentials. You want to identify which systems in the domain the account can access administratively, so you can plan lateral movement. Which approach most efficiently maps that access?
HardOther domains
All PEN-200 exam domains
Frequently asked questions
- What does the Enumeration and Reconnaissance domain cover on the PEN-200 exam?
- You must be able to run and read Nmap scans, interpret ICMP and TCP responses, and enumerate DNS and services to build a target picture. The single most important skill is correctly distinguishing open, closed, and filtered states and what each reveals about the target's firewall and host status.
- How many questions are in this domain?
- This page lists all 33 Enumeration and Reconnaissance questions in the PEN-200 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Enumeration and Reconnaissance questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.