PEN-200 Enumeration and Reconnaissance Practice Question
During an internal penetration test, you have captured network traffic and identified a host that responds on TCP port 445. You want to gather detailed information about the SMB service, including the operating system version, NetBIOS name, and domain, without authenticating. Which Nmap NSE script is most appropriate for this task?
⚠ Common exam trap
Watch out — candidates often confuse SMB enumeration scripts that require authentication with those that can extract host information anonymously.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
smb-os-discovery
The smb-os-discovery script is designed to query SMB services for host details such as operating system, NetBIOS name, and domain without requiring credentials. Other SMB scripts focus on shares, brute-forcing, or vulnerability checks, which do not provide the required enumeration data. Therefore, smb-os-discovery is the correct tool for this task.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
smb-vuln-ms17-010
Why it's wrong here
This script checks for the MS17-010 vulnerability (EternalBlue) and does not enumerate general host information like OS version or NetBIOS name. While useful for vulnerability assessment, it does not fulfill the goal of gathering detailed SMB service information without authentication.
- ✗
smb-brute
Why it's wrong here
This script performs brute-force attacks against SMB authentication, attempting to guess usernames and passwords. It is used for credential discovery, not for passive enumeration of host details. It would generate excessive traffic and likely lock accounts, and does not provide OS or NetBIOS information.
- ✓
smb-os-discovery
Why this is correct
This script attempts to connect to the SMB service and extract the OS version, NetBIOS name, domain, and other details without requiring credentials. It is specifically designed for unauthenticated enumeration of SMB hosts and is part of the default Nmap Scripting Engine library. It is the correct choice for the scenario.
- ✗
smb-enum-shares
Why it's wrong here
This script enumerates SMB shares but does not provide OS version, NetBIOS name, or domain information. It focuses on listing shares and their permissions, which may require authentication for full results. It does not meet the requirement to gather the specified host details without authenticating.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.