PEN-200 Enumeration and Reconnaissance Practice Question
During an internal penetration test, you run a UDP scan against a Linux server and see the following result: `161/udp open snmp`. You want to extract as much host information as possible without triggering authentication failures. Which command should you run first?
⚠ Common exam trap
The trap here is assuming SNMP enumeration requires brute-forcing community strings, when the default `public` string is often still enabled and yields immediate results.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
`snmpwalk -v2c -c public 10.10.10.25`
The most efficient first action is to query SNMP with the default read-only community string using `snmpwalk`. It both confirms the service is accessible and dumps a large amount of host data in one step. Brute-forcing or using SNMPv3 credentials is premature and risks detection or lockout without adding immediate value.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
`onesixtyone -c /usr/share/seclists/Discovery/SNMP/common-snmp-community-strings.txt 10.10.10.25`
Why it's wrong here
`onesixtyone` brute-forces community strings, which is useful when the default `public` string fails. However, it only identifies the community string; it does not retrieve the rich MIB data. Since `public` is the most common default and `snmpwalk` both validates it and extracts information, brute-forcing first is less efficient and may trigger SNMP threshold alerts.
- ✗
`snmpwalk -v3 -l authPriv -u admin -a SHA -A password 10.10.10.25`
Why it's wrong here
SNMPv3 with `authPriv` requires valid credentials you do not yet possess. Supplying guessed credentials will fail authentication and can generate log entries, violating the goal of avoiding authentication failures. This command is appropriate only after you have discovered valid SNMPv3 user credentials, not as the initial enumeration step.
- ✓
`snmpwalk -v2c -c public 10.10.10.25`
Why this is correct
SNMPv2c with the default community string `public` is commonly left enabled on Linux servers, and `snmpwalk` recursively walks the MIB tree to reveal system description, interfaces, routes, users, and installed software. It is a read operation that does not attempt authentication, so it gathers maximum information without locking accounts or generating failed-login events.
- ✗
`nmap -sU -p161 --script snmp-brute 10.10.10.25`
Why it's wrong here
The `snmp-brute` NSE script attempts to guess community strings by brute force, which is slower than a single `snmpwalk` with the default string and may generate many failed requests. It also does not provide the same depth of MIB enumeration as `snmpwalk`. This is a fallback option, not the most efficient first command.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.