Courseiva

PEN-200 Enumeration and Reconnaissance Practice Question

During enumeration you discover a DNS server that allows zone transfers to any client. What is the most valuable outcome of performing a successful AXFR against this server?

⚠ Common exam trap

The trap here is inflating a zone transfer into full server compromise, when it actually only discloses the zone's public record data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Obtaining a complete list of hostnames and IP addresses defined in the zone, revealing internal naming and structure.

An unrestricted AXFR hands over the entire zone contents, including internal hostnames, address records, and service pointers that are otherwise difficult to enumerate. This produces a detailed map of the organization's naming scheme and reachable systems. It does not grant server control, expose signing keys, or decrypt past traffic, so the real value lies in the breadth of hostname and address intelligence revealed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Decrypting previously captured DNS query traffic between clients and the server.

    Why it's wrong here

    A zone transfer is a separate query for record data and provides no cryptographic material to decrypt prior traffic. It does not retroactively reveal past query contents. Treating AXFR as a decryption method conflates data disclosure with cryptanalysis and does not match how DNS record replication behaves.

  • ✗

    Gaining administrative control over the DNS server's configuration files.

    Why it's wrong here

    A zone transfer only reads zone data; it does not grant write access or shell on the server. Misconfiguring the transfer ACL exposes records but leaves configuration files untouched. Confusing read-only data exposure with system compromise overstates the impact and points remediation at the wrong control.

  • ✓

    Obtaining a complete list of hostnames and IP addresses defined in the zone, revealing internal naming and structure.

    Why this is correct

    A successful AXFR returns every record in the zone, exposing hostnames, subdomains, mail servers, and address mappings that are normally hidden. This comprehensive inventory reveals internal naming conventions and network layout, giving an attacker a detailed map of reachable systems far beyond what individual queries would disclose.

  • ✗

    Retrieving the server's private TLS keys used to sign DNSSEC records.

    Why it's wrong here

    DNSSEC signing keys are never distributed via AXFR; the transfer carries public resource records such as A, MX, and NS entries. Private keys stay on the signing infrastructure. Expecting key material from a zone transfer reflects a misunderstanding of what record data the protocol actually replicates.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.