Courseiva

PEN-200 · domain

Enumeration and Reconnaissance

This domain covers active and passive information gathering before exploitation: host discovery, port and service scanning with Nmap, DNS and infrastructure enumeration, and interpreting scan responses correctly. PEN-200 tests it through scenario questions where you must choose the right scan type or tool and infer host state from ICMP, TCP, and RST/ACK behavior.

33 questions6 easy18 medium9 hard

Focused practice

Practice Enumeration and Reconnaissance questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Enumeration and Reconnaissance

You must be able to run and read Nmap scans, interpret ICMP and TCP responses, and enumerate DNS and services to build a target picture. The single most important skill is correctly distinguishing open, closed, and filtered states and what each reveals about the target's firewall and host status.

Interpreting Nmap port states (open, closed, filtered) and what each implies about firewalls

Choosing scan types such as TCP SYN, connect, UDP, and ICMP echo for a given target

Enumerating DNS records (A, MX, NS, TXT) and mapping mail or name infrastructure

Using Nmap service/version detection and tools like nslookup, dig, and whois

Watch out for

Common Enumeration and Reconnaissance exam traps

  • ▸Assuming filtered ports mean the host is down, when a firewall may simply be dropping probes
  • ▸Confusing RST/ACK replies (closed port) with no response (filtered) during SYN scans
  • ▸Treating MX records as direct mail server IPs instead of resolving the hostname first

Question index

All Enumeration and Reconnaissance questions (33)

Click any question to see the full explanation, or start a practice session above.

1

During enumeration you discover a DNS server that allows zone transfers to any client. What is the most valuable outcome of performing a successful AXFR against this server?

Hard
2

You are performing reconnaissance and want to identify if a target website uses a specific CMS like WordPress. What is the most effective approach?

Medium
3

Refer to the exhibit. You have scanned a target and obtained these results. Which step is most logical to perform next to effectively enumerate the web service?

Medium
4

You are enumerating a Linux host and discover TCP port 2049 open. You need to determine what is being exported and to whom before deciding on any exploitation path. Which action most directly answers that question?

Medium
5

Which THREE of the following are considered 'active' reconnaissance techniques, as opposed to passive techniques?

Hard
6

Which TWO of the following techniques are most effective for enumerating SMB shares on a Windows host during a penetration test?

Medium
7

During an external penetration test, you discover a web server hosting multiple virtual hosts. You want to enumerate additional hostnames that resolve to the same IP address without triggering intrusion detection systems. Which technique is most appropriate?

Hard
8

During an internal penetration test, you have captured network traffic and identified a host that responds on TCP port 445. You want to gather detailed information about the SMB service, including the operating system version, NetBIOS name, and domain, without authenticating. Which Nmap NSE script is most appropriate for this task?

Medium
9

You are performing web enumeration against a target application and want to discover hidden directories, backup files, and administrative interfaces that are not linked from the visible pages. Which two approaches are most appropriate for this goal? (Choose two.)

Medium
10

During an internal assessment you receive a scope that lists a /24 subnet but explicitly forbids any traffic that could cause service disruption. You need to identify live hosts and open TCP ports while keeping the scan as quiet and non-intrusive as possible. Which single Nmap invocation best matches these constraints?

Hard
11

When performing reconnaissance on an unknown network, you discover a service running on port 161. What is the most appropriate action to take to determine if this service can be abused?

Hard
12

You are enumerating a Linux host and find that UDP port 161 responds to SNMP queries with the community string 'public'. Which action yields the most useful reconnaissance data for planning later exploitation?

Hard
13

You are performing a network scan on a client segment and notice that a host responds to ICMP echo requests but shows all TCP ports as 'filtered' when using Nmap. Which conclusion is most accurate?

Medium
14

You are enumerating a Linux target and discover that TCP port 2049 is open. You run `showmount -e 192.168.1.100` and see that the `/home` directory is exported to everyone. What is the most significant security risk this configuration presents?

Medium
15

You are performing active reconnaissance against a web server and want to identify hidden directories and files that may not be linked from the main site. Which two techniques are most appropriate for this goal? (Choose two.)

Hard
16

Refer to the exhibit. Based on the HTTP response headers provided, what critical information can be gathered for your reconnaissance?

Medium
17

You have successfully identified a Windows target and need to perform deep enumeration. Which TWO techniques are most effective for identifying hidden local services and internal network connections?

Medium
18

You are conducting a penetration test and need to identify the operating system of a target host without sending any packets to it. Which of the following methods is most appropriate?

Easy
19

During an internal penetration test, you run a UDP scan against a Linux server and see the following result: `161/udp open snmp`. You want to extract as much host information as possible without triggering authentication failures. Which command should you run first?

Medium
20

During a network assessment, you want to enumerate users on a domain controller. Which protocol and port combination is the most standard target for this type of enumeration?

Medium
21

Which TWO of the following actions are considered best practice during the initial host enumeration phase to avoid detection by security monitoring tools?

Medium
22

When enumerating a web application, which THREE of the following items are most important to identify to increase the likelihood of finding a vulnerability?

Hard
23

Refer to the exhibit. Which ports are currently open on the target host 192.168.1.10?

Easy
24

While mapping a subnet you want to discover live hosts quickly before running detailed service scans. Which approach best fits an initial host-discovery sweep?

Easy
25

During external reconnaissance you collect DNS records for a target organization and find an MX record pointing to mail.example.com. You want to identify the IP addresses of other hosts in the same mail infrastructure without sending any packets directly to the target's servers. Which action best fits this passive goal?

Easy
26

During an internal assessment you run a TCP SYN scan and note that a host responds with an RST/ACK for every probed port. What does this behavior most reliably indicate about the target host?

Medium
27

Which command-line tool is primarily used during the reconnaissance phase to identify open ports and service versions on a remote target?

Easy
28

During a penetration test, you need to enumerate DNS records for the domain `example.com` to find subdomains and mail servers. Which command should you use to perform a zone transfer attempt?

Easy
29

You are performing a network scan on a target network and notice that ICMP echo requests are blocked, but you need to determine if the target host is alive. Which technique should you utilize to identify active hosts without relying on standard ICMP ping?

Medium
30

You have identified an open port 445 on a Windows machine. Which tool is most effective for checking if the machine is vulnerable to common SMB-based exploits like EternalBlue?

Medium
31

You need to fingerprint the web server technology behind an HTTP service without sending malformed or intrusive requests. Which two actions best accomplish passive-leaning banner and behavior fingerprinting during enumeration? (Choose two.)

Medium
32

You are enumerating an Apache web server and discover the '.git' directory is accessible. What is the most significant risk this poses for your reconnaissance?

Medium
33

You are enumerating a Windows host and have obtained valid low-privilege domain credentials. You want to identify which systems in the domain the account can access administratively, so you can plan lateral movement. Which approach most efficiently maps that access?

Hard

Frequently asked questions

What does the Enumeration and Reconnaissance domain cover on the PEN-200 exam?
You must be able to run and read Nmap scans, interpret ICMP and TCP responses, and enumerate DNS and services to build a target picture. The single most important skill is correctly distinguishing open, closed, and filtered states and what each reveals about the target's firewall and host status.
How many questions are in this domain?
This page lists all 33 Enumeration and Reconnaissance questions in the PEN-200 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Enumeration and Reconnaissance questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
offsec-oscp OFFSEC-OSCP enumeration and reconnaissance Practice Questions