PEN-200 Enumeration and Reconnaissance Practice Question
During enumeration you discover a DNS server that allows zone transfers to any client. What is the most valuable outcome of performing a successful AXFR against this server?
⚠ Common exam trap
The trap here is inflating a zone transfer into full server compromise, when it actually only discloses the zone's public record data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Obtaining a complete list of hostnames and IP addresses defined in the zone, revealing internal naming and structure.
An unrestricted AXFR hands over the entire zone contents, including internal hostnames, address records, and service pointers that are otherwise difficult to enumerate. This produces a detailed map of the organization's naming scheme and reachable systems. It does not grant server control, expose signing keys, or decrypt past traffic, so the real value lies in the breadth of hostname and address intelligence revealed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Decrypting previously captured DNS query traffic between clients and the server.
Why it's wrong here
A zone transfer is a separate query for record data and provides no cryptographic material to decrypt prior traffic. It does not retroactively reveal past query contents. Treating AXFR as a decryption method conflates data disclosure with cryptanalysis and does not match how DNS record replication behaves.
- ✗
Gaining administrative control over the DNS server's configuration files.
Why it's wrong here
A zone transfer only reads zone data; it does not grant write access or shell on the server. Misconfiguring the transfer ACL exposes records but leaves configuration files untouched. Confusing read-only data exposure with system compromise overstates the impact and points remediation at the wrong control.
- ✓
Obtaining a complete list of hostnames and IP addresses defined in the zone, revealing internal naming and structure.
Why this is correct
A successful AXFR returns every record in the zone, exposing hostnames, subdomains, mail servers, and address mappings that are normally hidden. This comprehensive inventory reveals internal naming conventions and network layout, giving an attacker a detailed map of reachable systems far beyond what individual queries would disclose.
- ✗
Retrieving the server's private TLS keys used to sign DNSSEC records.
Why it's wrong here
DNSSEC signing keys are never distributed via AXFR; the transfer carries public resource records such as A, MX, and NS entries. Private keys stay on the signing infrastructure. Expecting key material from a zone transfer reflects a misunderstanding of what record data the protocol actually replicates.
Visual reference
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.