Courseiva

PEN-200 Enumeration and Reconnaissance Practice Question

During a penetration test, you need to enumerate DNS records for the domain `example.com` to find subdomains and mail servers. Which command should you use to perform a zone transfer attempt?

⚠ Common exam trap

Watch out — candidates often confuse general DNS enumeration tools with the specific AXFR query needed for a zone transfer attempt.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

`dig axfr @ns1.example.com example.com`

The `dig axfr` command is the direct way to request a zone transfer from a name server. It targets the specific DNS server and domain, and if the server allows transfers, it returns the full zone file. Other commands may perform DNS queries but do not explicitly request a zone transfer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    `nslookup -type=any example.com`

    Why it's wrong here

    `nslookup -type=any` queries for any available records but does not request a zone transfer. It may return some records, but it will not dump the entire zone. It is useful for general DNS enumeration but does not perform the specific AXFR request needed to test for zone transfer misconfigurations.

  • ✗

    `host -l example.com ns1.example.com`

    Why it's wrong here

    The `host -l` command attempts a zone transfer, but it is less commonly used and may not work with all DNS servers. `dig axfr` is the more reliable and widely supported tool for this purpose. While `host -l` can succeed, it is not the preferred choice for a zone transfer attempt in a penetration test.

  • ✗

    `dnsenum --enum example.com`

    Why it's wrong here

    `dnsenum` is a comprehensive DNS enumeration tool that can attempt zone transfers as part of its process, but it performs many other queries as well. The question asks for the command to perform a zone transfer attempt specifically, and `dig axfr` is the direct, focused command for that task. `dnsenum` is broader but less precise.

  • ✓

    `dig axfr @ns1.example.com example.com`

    Why this is correct

    The `axfr` option in `dig` requests a full zone transfer from the specified name server. If the server is misconfigured to allow transfers from any host, it will return all DNS records for the domain, revealing subdomains, mail servers, and other hosts. This is the standard command for attempting a zone transfer.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.