Courseiva

CCNA Enumeration And Reconnaissance Questions

33 questions · Enumeration And Reconnaissance topic · All types, answers revealed

1
MCQhard

During enumeration you discover a DNS server that allows zone transfers to any client. What is the most valuable outcome of performing a successful AXFR against this server?

A.Decrypting previously captured DNS query traffic between clients and the server.
B.Gaining administrative control over the DNS server's configuration files.
C.Obtaining a complete list of hostnames and IP addresses defined in the zone, revealing internal naming and structure.
D.Retrieving the server's private TLS keys used to sign DNSSEC records.
AnswerC

A successful AXFR returns every record in the zone, exposing hostnames, subdomains, mail servers, and address mappings that are normally hidden. This comprehensive inventory reveals internal naming conventions and network layout, giving an attacker a detailed map of reachable systems far beyond what individual queries would disclose.

Why this answer

An unrestricted AXFR hands over the entire zone contents, including internal hostnames, address records, and service pointers that are otherwise difficult to enumerate. This produces a detailed map of the organization's naming scheme and reachable systems. It does not grant server control, expose signing keys, or decrypt past traffic, so the real value lies in the breadth of hostname and address intelligence revealed.

Exam trap

The trap here is inflating a zone transfer into full server compromise, when it actually only discloses the zone's public record data.

2
MCQmedium

You are performing reconnaissance and want to identify if a target website uses a specific CMS like WordPress. What is the most effective approach?

A.Manually inspect every image on the site.
B.Use tools like whatweb or Wappalyzer.
C.Perform a denial-of-service attack.
D.Guess the CMS by looking at the page title.
AnswerB

Whatweb and Wappalyzer are specialized reconnaissance tools that automatically detect the software stack, including the CMS, by analyzing server headers and page source code. This is the professional standard for quickly identifying the application framework, which is essential for tailoring your exploitation strategy to the specific target platform.

Why this answer

Automated tools like 'wappalyzer' or 'whatweb' are highly effective at identifying the underlying technology stack of a web application. They analyze HTTP headers, source code patterns, and common file paths to detect CMS platforms. Identifying the CMS is critical because it allows the tester to focus on known vulnerabilities associated with that specific platform, rather than spending time on generic web assessments that may yield fewer results.

Exam trap

Candidates often suggest manual source code inspection. Automated tools are far more efficient and reliable for identifying the CMS signature across various HTTP headers and file paths.

3
MCQmedium

Refer to the exhibit. You have scanned a target and obtained these results. Which step is most logical to perform next to effectively enumerate the web service?

A.Immediately attempt to exploit the FTP service with anonymous login.
B.Perform directory busting using tools like ffuf or gobuster.
C.Brute-force the SSH service using a list of common passwords.
D.Run a full vulnerability scanner against the entire target IP.
AnswerB

Directory busting helps discover unlinked files and directories that could contain sensitive information, backups, or administrative interfaces. This enumeration phase is vital because many web applications rely on security by obscurity, and finding these hidden paths often provides the necessary leverage for a successful penetration test and further exploitation.

Why this answer

After identifying open ports, the next logical step is to enumerate the specific services running. For port 80, web directory brute-forcing is essential to uncover hidden administrative panels or configuration files that might not be linked on the home page. This systematic approach ensures no low-hanging fruit is missed, providing a deeper understanding of the target's attack surface before attempting any vulnerability exploitation against the identified web application or services.

Exam trap

Candidates often attempt to immediately brute-force web login pages or run heavy vulnerability scanners without first discovering hidden directories and files.

4
MCQmedium

You are enumerating a Linux host and discover TCP port 2049 open. You need to determine what is being exported and to whom before deciding on any exploitation path. Which action most directly answers that question?

A.Run showmount -e <target> to list exported filesystems and permitted clients.
B.Run smbclient -L //<target> -N to list available SMB shares.
C.Use ftp <target> 2049 and authenticate anonymously to browse the share.
D.Connect with rdesktop <target>:2049 to inspect the remote desktop session.
AnswerA

Port 2049 is NFS, and showmount -e queries the target's mount daemon to display each exported share along with the host or subnet allowed to mount it. That output directly answers what is exported and to whom, which is exactly the reconnaissance objective. It is a lightweight, standard query that does not modify anything on the server, making it the most direct and appropriate next step.

Why this answer

NFS enumeration centers on the mount protocol, which advertises exported directories and the client hosts or networks authorized to mount them. The showmount utility with the -e flag performs exactly that query against the target. Other tools suggested here speak SMB, RDP, or FTP, none of which correspond to the NFS service listening on port 2049, so they cannot reveal export details or access restrictions.

Exam trap

The trap here is treating any open file-sharing port as SMB and reaching for smbclient instead of matching the tool to the NFS service on port 2049.

5
Multi-Selecthard

Which THREE of the following are considered 'active' reconnaissance techniques, as opposed to passive techniques?

Select 3 answers
A.Port scanning with Nmap.
B.Service version detection.
C.Directory brute-forcing.
D.WHOIS lookup.
E.Searching Google for public documents.
AnswersA, B, C

Port scanning requires sending packets directly to the target system to determine if specific ports are open. This interaction is recorded in logs and constitutes a clear 'active' action, as the target system must process and reply to the probes, making it a highly visible reconnaissance technique.

Why this answer

Active reconnaissance involves direct interaction with the target system, which creates a visible footprint in server logs. Techniques like port scanning, service version detection, and directory brute-forcing are all active because they involve sending packets that the target must respond to. In contrast, passive reconnaissance uses third-party services to gather information without touching the target.

Understanding this distinction is vital for maintaining the desired level of stealth throughout the reconnaissance and exploitation process.

Exam trap

Candidates often misidentify banner grabbing or simple DNS lookups as active. Active reconnaissance requires direct interaction that generates logs on the target system, unlike passive OSINT gathering.

6
Multi-Selectmedium

Which TWO of the following techniques are most effective for enumerating SMB shares on a Windows host during a penetration test?

Select 2 answers
A.Use smbclient -L //target_ip -N to list available shares.
B.Run nmap with the --script smb-enum-shares scan argument.
C.Perform a brute-force attack on the C$ share.
D.Attempt to ping the host using ICMP to check SMB connectivity.
E.Use the telnet command to connect to port 445.
AnswersA, B

The smbclient tool is the standard Linux utility for interacting with SMB shares. The -L flag queries the target for a list of shares, and the -N flag specifies no password, which is essential when testing for null sessions or guest access that might be improperly enabled on the target.

Why this answer

Enumerating SMB shares is crucial for identifying sensitive data, configuration files, or scripts that can lead to privilege escalation. Tools like smbclient and specialized scripts allow testers to interact with the SMB protocol to list shares and check for null sessions. Understanding these methods is fundamental for gathering intelligence in Windows environments, as misconfigured SMB permissions often provide an easy path to sensitive information and potential system compromise.

Exam trap

Candidates often forget specific syntax parameters or use tools that require active domain credentials when attempting unauthenticated SMB enumeration like null sessions.

7
MCQhard

During an external penetration test, you discover a web server hosting multiple virtual hosts. You want to enumerate additional hostnames that resolve to the same IP address without triggering intrusion detection systems. Which technique is most appropriate?

A.Query public Certificate Transparency logs for certificates issued for the target domain.
B.Send HTTP requests with different Host headers to the web server and analyze responses.
C.Perform a DNS zone transfer (AXFR) against the authoritative name server.
D.Use a reverse DNS sweep of the IP address range to identify PTR records.
AnswerA

Certificate Transparency (CT) logs are public, passive sources that record every SSL/TLS certificate issued by participating CAs. Searching CT logs for the target domain can reveal subdomains and virtual hostnames without sending any traffic to the target. This is a passive reconnaissance technique that does not trigger IDS because you are querying third-party logs, not the target.

Why this answer

Certificate Transparency logs are a passive reconnaissance resource that aggregates certificates issued for domains. By querying these logs, you can discover subdomains and virtual hostnames without interacting with the target. This avoids IDS alerts and is a standard OSINT technique.

The other options involve active scanning or noisy DNS queries that are more likely to be detected.

Exam trap

The trap here is assuming that any enumeration method that does not directly connect to the target is passive, when in fact reverse DNS sweeps and zone transfer attempts still generate traffic that can be logged and flagged.

8
MCQmedium

During an internal penetration test, you have captured network traffic and identified a host that responds on TCP port 445. You want to gather detailed information about the SMB service, including the operating system version, NetBIOS name, and domain, without authenticating. Which Nmap NSE script is most appropriate for this task?

A.smb-vuln-ms17-010
B.smb-brute
C.smb-os-discovery
D.smb-enum-shares
AnswerC

This script attempts to connect to the SMB service and extract the OS version, NetBIOS name, domain, and other details without requiring credentials. It is specifically designed for unauthenticated enumeration of SMB hosts and is part of the default Nmap Scripting Engine library. It is the correct choice for the scenario.

Why this answer

The smb-os-discovery script is designed to query SMB services for host details such as operating system, NetBIOS name, and domain without requiring credentials. Other SMB scripts focus on shares, brute-forcing, or vulnerability checks, which do not provide the required enumeration data. Therefore, smb-os-discovery is the correct tool for this task.

Exam trap

The trap here is confusing SMB enumeration scripts that require authentication with those that can extract host information anonymously.

9
Multi-Selectmedium

You are performing web enumeration against a target application and want to discover hidden directories, backup files, and administrative interfaces that are not linked from the visible pages. Which two approaches are most appropriate for this goal? (Choose two.)

Select 2 answers
A.Use the search engine operator site:target.com to enumerate internal directories.
B.Inspect the robots.txt and sitemap.xml files for disallowed or listed paths.
C.Run a content discovery tool such as Gobuster or Feroxbuster with a curated wordlist against the web root.
D.Send a single HTTP GET request to the web root and review the returned status code.
E.Perform a full TCP port scan of the web server to reveal application directories.
AnswersB, C

robots.txt frequently lists directories that administrators want excluded from crawlers, which often correlates with sensitive or administrative areas. Sitemap.xml enumerates pages the site owner considers important. Both are publicly accessible and cost almost nothing to retrieve, and they routinely surface paths that are not linked in navigation menus. That makes them a high-value, low-noise source for discovering hidden or restricted areas during enumeration.

Why this answer

Discovering unlinked web content requires either actively probing candidate paths with a wordlist-driven tool or harvesting the metadata files administrators use to guide crawlers. Content discovery tools test many paths and interpret responses, while robots.txt and sitemap.xml often expose restricted or sensitive directories directly. Passive search operators, port scans, and a single root request all fail to reveal paths that are not linked or already indexed.

Exam trap

The trap here is assuming that search engine indexing or a single root request counts as web enumeration, when unlinked content only appears through active path brute forcing or metadata file inspection.

10
MCQhard

During an internal assessment you receive a scope that lists a /24 subnet but explicitly forbids any traffic that could cause service disruption. You need to identify live hosts and open TCP ports while keeping the scan as quiet and non-intrusive as possible. Which single Nmap invocation best matches these constraints?

A.nmap -sS -T2 --top-ports 100 10.10.10.0/24
B.nmap -sS -T4 -p- 10.10.10.0/24
C.nmap -sn 10.10.10.0/24
D.nmap -sU -T4 --min-rate 5000 10.10.10.0/24
AnswerA

A half-open SYN scan with -T2 timing and only the most common 100 ports balances coverage and stealth. SYN scanning never completes the TCP handshake, reducing load on target services, while -T2 slows packet delivery to avoid overwhelming hosts or triggering rate-based alarms. Limiting to top ports keeps the footprint small, which directly satisfies the non-disruptive requirement while still identifying live hosts and their common open TCP ports.

Why this answer

Balancing reconnaissance depth against a no-disruption clause requires a scan that avoids full TCP connections, throttles its own packet rate, and limits the port set. A half-open SYN scan with conservative timing and a small top-ports list achieves host discovery plus meaningful TCP port enumeration without stressing services. Full-range or high-rate scans and UDP sweeps either overload targets or answer a different question than the one asked.

Exam trap

The trap here is assuming that any SYN scan is automatically stealthy, when timing templates and port range determine how disruptive the scan actually is.

11
MCQhard

When performing reconnaissance on an unknown network, you discover a service running on port 161. What is the most appropriate action to take to determine if this service can be abused?

A.Attempt a brute-force attack on the SSH service.
B.Use snmpwalk to attempt to retrieve data using default community strings.
C.Run a full Nmap script scan for all protocols.
D.Ignore the port as it is rarely used for anything critical.
AnswerB

Snmpwalk is the standard tool for querying SNMP agents. Testing common default community strings is the industry-standard initial step for enumerating SNMP. If the agent responds, it reveals a wealth of information about the target's configuration, which is essential for informed decision-making during the subsequent stages of testing.

Why this answer

Port 161 is the default port for SNMP (Simple Network Management Protocol). Often, SNMP is misconfigured with default community strings like 'public' or 'private'. By testing these strings, a tester can potentially retrieve sensitive system information such as running processes, network interfaces, and even user accounts.

This is a classic, high-value enumeration target that frequently yields significant information for further lateral movement or privilege escalation within the network environment.

Exam trap

Candidates often suggest port scanning or full vulnerability scans. The most effective first step for SNMP is using specific enumeration tools like snmpwalk to test default community strings for information.

12
MCQhard

You are enumerating a Linux host and find that UDP port 161 responds to SNMP queries with the community string 'public'. Which action yields the most useful reconnaissance data for planning later exploitation?

A.Run snmpwalk against the device to dump the MIB tree and extract system and interface information.
B.Send SNMP traps to the device to force it to report its running configuration.
C.Use the community string to authenticate to the device over SSH on port 22.
D.Attempt an SNMP write operation using the same community string to alter device configuration.
AnswerA

With a valid read-only community string, snmpwalk traverses the Management Information Base and returns system description, interfaces, routing tables, and sometimes process or user data. This structured output directly feeds later phases by revealing OS versions, network topology, and potential pivot points, making it the highest-value follow-up action here.

Why this answer

A working SNMP community string grants read access to the Management Information Base, and snmpwalk systematically dumps that tree. The resulting system descriptions, interface listings, and routing data give concrete enumeration value, exposing OS details and network layout that guide subsequent exploitation far better than any write, authentication, or trap-based approach.

Exam trap

The trap here is treating an SNMP community string as a reusable credential for other services instead of a read key for the MIB.

13
MCQmedium

You are performing a network scan on a client segment and notice that a host responds to ICMP echo requests but shows all TCP ports as 'filtered' when using Nmap. Which conclusion is most accurate?

A.The target machine is powered off and the ICMP response is generated by a gateway device.
B.The target host is running a non-standard TCP/IP stack that ignores all incoming connection attempts.
C.A network-based firewall is likely dropping incoming TCP packets while allowing ICMP traffic to pass through.
D.The network interface on the target machine is misconfigured and unable to process TCP/IP traffic.
AnswerC

Nmap reports 'filtered' when it cannot determine if a port is open because probes are blocked. Since ICMP succeeds, the host is alive, but TCP packets are being dropped by a firewall. This is a common scenario in enterprise environments where ICMP is permitted for monitoring but TCP access is restricted.

Why this answer

The 'filtered' status indicates that a firewall or packet-filtering device is likely intercepting the TCP SYN packets and dropping them or sending prohibited ICMP error messages. Since the host responds to ICMP, the host is live, but the network path or host-based firewall prevents TCP probing. Understanding this distinction is critical for pivoting strategies and determining if the target's attack surface is truly closed or merely protected by perimeter security controls.

Exam trap

Candidates often assume the host is down or the scan is faulty because ports show as filtered, failing to recognize that ICMP responses confirm the host is active despite TCP-level blocking.

14
MCQmedium

You are enumerating a Linux target and discover that TCP port 2049 is open. You run `showmount -e 192.168.1.100` and see that the `/home` directory is exported to everyone. What is the most significant security risk this configuration presents?

A.The NFS service is vulnerable to a buffer overflow that allows remote code execution.
B.An attacker can use the NFS share to perform a denial-of-service attack by filling the disk.
C.The NFS share allows anonymous FTP access to the same directory.
D.An attacker can mount the share and read or modify any user's home directory files, potentially leading to privilege escalation.
AnswerD

When NFS exports a directory to everyone (i.e., world-readable and writable), any remote attacker can mount it without authentication. This grants access to all files within /home, including sensitive data like SSH keys, configuration files, and scripts. If writable, an attacker could inject malicious code or modify authorized_keys to escalate privileges.

Why this answer

An NFS export to everyone allows any attacker to mount the share without authentication, gaining read and write access to the /home directory. This can lead to theft of SSH keys, modification of scripts, or insertion of malicious code, ultimately enabling privilege escalation or lateral movement. The other options either describe unrelated vulnerabilities or less severe impacts.

Exam trap

The trap here is focusing on potential software vulnerabilities or DoS when the real issue is the misconfigured export that grants unauthenticated access to sensitive user data.

15
Multi-Selecthard

You are performing active reconnaissance against a web server and want to identify hidden directories and files that may not be linked from the main site. Which two techniques are most appropriate for this goal? (Choose two.)

Select 2 answers
A.Running a full TCP port scan with Nmap to identify all open ports on the server.
B.Using a tool like Gobuster with a wordlist to brute-force common directory and file names.
C.Inspecting the robots.txt file for disallowed entries that may reveal sensitive paths.
D.Performing a WHOIS lookup to gather registration details about the domain.
E.Using the `dig` command to perform a zone transfer on the DNS server.
AnswersB, C

Gobuster is a specialized tool for brute-forcing URIs (directories and files) on web servers. It sends HTTP requests for each word in a wordlist and analyzes the response codes to identify existing resources. This is a standard active reconnaissance technique to discover hidden content that is not linked from the visible site.

Why this answer

Brute-forcing with Gobuster and inspecting robots.txt are both effective for discovering hidden directories and files on a web server. Gobuster actively probes for common names, while robots.txt may list disallowed paths that administrators wish to keep out of search engines. The other techniques focus on port scanning, DNS, or registration data, which do not directly enumerate web content.

Exam trap

The trap here is confusing port scanning or DNS enumeration with web content discovery; only techniques that interact with the web server at the HTTP layer will reveal hidden directories and files.

16
MCQmedium

Refer to the exhibit. Based on the HTTP response headers provided, what critical information can be gathered for your reconnaissance?

A.The operating system is exclusively Windows.
B.The web server version and PHP version are disclosed.
C.The database being used is Microsoft SQL Server.
D.The application is currently configured for debugging mode.
AnswerB

The headers contain clear information about the server software, Apache 2.4.41, and the scripting engine, PHP 7.4.3. This version disclosure is a major vulnerability in itself, as it allows attackers to quickly look up public CVEs associated with these specific versions and plan their next steps accordingly.

Why this answer

The headers explicitly disclose the web server (Apache 2.4.41) and the application framework (PHP 7.4.3). This is crucial intelligence because these specific versions may have known vulnerabilities or CVEs associated with them. By identifying the exact software stack, you can tailor your future exploitation efforts to target the specific weaknesses documented for these versions, significantly increasing the probability of a successful engagement and minimizing the noise generated by generic testing.

Exam trap

Candidates often ignore HTTP response headers, focusing only on the visual webpage content and missing critical server version disclosures.

17
Multi-Selectmedium

You have successfully identified a Windows target and need to perform deep enumeration. Which TWO techniques are most effective for identifying hidden local services and internal network connections?

Select 2 answers
A.Execute 'netstat -ano' to identify local listening ports and associated process IDs.
B.Run 'nmap -sS -p- 127.0.0.1' from the target machine to map all possible services.
C.Use 'wmic service get name,displayname,state,startmode' to list all configured services.
D.Analyze the 'hosts' file to find hidden DNS records for internal applications.
E.Check the system event logs for recent login attempts by administrative users.
AnswersA, C

The 'netstat -ano' command provides a comprehensive view of all active network connections and listening ports, including the specific process IDs (PIDs) associated with them. This is a foundational step in identifying locally bound services that are not accessible from the external network but are reachable via local exploitation.

Why this answer

Enumerating internal connections and services is essential for identifying lateral movement paths or local-only management interfaces. Using netstat confirms listening sockets that may not be exposed to the external network. Simultaneously, querying the Service Control Manager allows for the discovery of non-standard or custom services that might not be detected by typical port scans.

Mastering these OS-specific enumeration techniques significantly increases the likelihood of finding vulnerabilities in non-obvious entry points.

Exam trap

Candidates rely solely on external port scans and completely forget to run internal OS-level enumeration commands to find hidden local-only services.

18
MCQeasy

You are conducting a penetration test and need to identify the operating system of a target host without sending any packets to it. Which of the following methods is most appropriate?

A.Reviewing publicly available information such as job postings or technology stack details on the company's website.
B.Analyzing the Time-to-Live (TTL) values from a ping response.
C.Using Nmap's OS detection (-O) against the target IP address.
D.Performing a banner grab by connecting to open ports like 22 or 80.
AnswerA

Reviewing publicly available information is a passive reconnaissance technique that does not involve any direct interaction with the target. Job postings might mention specific operating systems or technologies, and the website's technology stack can be inferred from headers or public profiles. This meets the requirement of sending no packets to the target.

Why this answer

Passive reconnaissance involves gathering information without directly interacting with the target. Reviewing public sources like job postings and website technology stacks can reveal the operating system without sending any packets. Active methods such as TTL analysis, Nmap OS detection, and banner grabbing all require sending packets to the target, violating the constraint.

Exam trap

The trap here is assuming that analyzing TTL values is passive because it uses ping responses, but it still requires sending packets to the target.

19
MCQmedium

During an internal penetration test, you run a UDP scan against a Linux server and see the following result: `161/udp open snmp`. You want to extract as much host information as possible without triggering authentication failures. Which command should you run first?

A.`onesixtyone -c /usr/share/seclists/Discovery/SNMP/common-snmp-community-strings.txt 10.10.10.25`
B.`snmpwalk -v3 -l authPriv -u admin -a SHA -A password 10.10.10.25`
C.`snmpwalk -v2c -c public 10.10.10.25`
D.`nmap -sU -p161 --script snmp-brute 10.10.10.25`
AnswerC

SNMPv2c with the default community string `public` is commonly left enabled on Linux servers, and `snmpwalk` recursively walks the MIB tree to reveal system description, interfaces, routes, users, and installed software. It is a read operation that does not attempt authentication, so it gathers maximum information without locking accounts or generating failed-login events.

Why this answer

The most efficient first action is to query SNMP with the default read-only community string using `snmpwalk`. It both confirms the service is accessible and dumps a large amount of host data in one step. Brute-forcing or using SNMPv3 credentials is premature and risks detection or lockout without adding immediate value.

Exam trap

The trap here is assuming SNMP enumeration requires brute-forcing community strings, when the default `public` string is often still enabled and yields immediate results.

20
MCQmedium

During a network assessment, you want to enumerate users on a domain controller. Which protocol and port combination is the most standard target for this type of enumeration?

A.HTTP on port 80
B.LDAP on port 389
C.FTP on port 21
D.SMTP on port 25
AnswerB

LDAP is the primary protocol for directory services in Windows domains. Connecting to port 389 allows for queries that can return lists of users, groups, and computers. This is a standard enumeration technique used to map the domain and prepare for further attacks like password spraying or credential harvesting.

Why this answer

LDAP, running on port 389, is the standard protocol for querying directory information in a Windows domain. By successfully connecting to the LDAP service, a tester can often dump user lists, group memberships, and other organizational data. Understanding this protocol is vital, as it provides the foundation for password spraying attacks and deeper reconnaissance within Active Directory, which is a common objective in enterprise penetration tests.

Exam trap

Candidates often confuse LDAP port 389 with Kerberos (88) or SMB (445) when specifically trying to query organizational domain user lists.

21
Multi-Selectmedium

Which TWO of the following actions are considered best practice during the initial host enumeration phase to avoid detection by security monitoring tools?

Select 2 answers
A.Perform a full port scan on all 65535 ports concurrently.
B.Prioritize passive reconnaissance using OSINT sources.
C.Implement scan rate-limiting to reduce traffic volume.
D.Use aggressive service detection flags in all scans.
E.Scan from the same IP address at all times.
AnswersB, C

Passive reconnaissance involves gathering information without directly interacting with the target, such as using search engines, public records, or WHOIS data. This is completely stealthy, as it leaves no trace on the target system or their network, making it an essential first step in any professional engagement.

Why this answer

To minimize detection, penetration testers should prioritize passive information gathering before engaging in active, noisy scanning. When active scanning is required, rate-limiting and targeting specific ports rather than performing a 'scan all' approach helps blend the traffic into normal network behavior. These practices are essential for maintaining the stealth required in professional engagements, ensuring that the tester remains undetected while collecting the necessary intelligence to identify high-value targets.

Exam trap

Candidates often include aggressive scanning techniques like 'full TCP connect scans'. The question asks for best practices to 'avoid detection', which mandates passive methods and rate-limited active traffic.

22
Multi-Selecthard

When enumerating a web application, which THREE of the following items are most important to identify to increase the likelihood of finding a vulnerability?

Select 3 answers
A.Hidden directories and files.
B.The web server software and version.
C.User input fields and URL parameters.
D.The color scheme of the website.
E.The number of images hosted on the server.
AnswersA, B, C

Hidden directories often contain configuration files, backup scripts, or administrative interfaces that lack proper authentication. Identifying these paths provides a significant advantage, as they may contain sensitive information or serve as entry points that bypass the main application's security controls, providing easier access for a penetration tester.

Why this answer

Effective web enumeration requires looking beyond the main page. Identifying hidden directories, software versions, and input fields allows a tester to map the attack surface comprehensively. By finding these components, a tester can research known vulnerabilities associated with specific technologies or test for common web flaws like SQL injection or cross-site scripting, which are frequently found in custom application code and forgotten administrative paths.

Exam trap

Candidates often focus only on finding a single vulnerability on the homepage, neglecting input fields, parameters, and hidden administrative directories.

23
MCQeasy

Refer to the exhibit. Which ports are currently open on the target host 192.168.1.10?

A.All ports from 1 to 1000.
B.Only port 22.
C.Ports 22 and 80.
D.No ports are open.
AnswerC

The scan report explicitly shows that ports 22/tcp and 80/tcp are in the 'open' state. Correctly identifying these ports is fundamental to the reconnaissance phase, as it provides the necessary roadmap for deciding which service to analyze further for potential vulnerabilities or configuration weaknesses during the engagement.

Why this answer

The Nmap output clearly indicates the state of the scanned ports. In this exhibit, ports 22 and 80 are explicitly listed as 'open', while 998 others are closed. Identifying these specific ports is the first step in mapping the target's attack surface.

Understanding how to read scan output is a core competency that allows a tester to prioritize their focus towards the services that are most likely to be exploitable.

Exam trap

Candidates often misread Nmap output columns, confusing filtered or closed ports with open ones, or missing secondary ports running non-standard services due to rushing.

24
MCQeasy

While mapping a subnet you want to discover live hosts quickly before running detailed service scans. Which approach best fits an initial host-discovery sweep?

A.Run an ICMP echo sweep combined with TCP SYN probes to common ports to identify responsive hosts.
B.Query the local ARP cache and enumerate only the entries already present.
C.Send UDP probes to port 53 on every address and treat any reply as proof of a live host.
D.Perform a full TCP connect scan of all ports against every address in the subnet range.
AnswerA

Combining ICMP echo with TCP SYN probes to frequently open ports catches hosts that block ping but still expose services, a common configuration. This layered discovery approach maximizes live-host detection quickly, providing a target list for later, more intensive service enumeration without wasting time scanning dead addresses.

Why this answer

Effective host discovery layers ICMP echo with TCP SYN probes to common ports, because many systems disable ping replies while still exposing services. This combination surfaces more live hosts faster than any single method, producing an accurate target list. Full port scans, single-port UDP probes, and ARP cache reads are either too slow, too unreliable, or too incomplete for an initial sweep.

Exam trap

The trap here is assuming ping alone identifies all live hosts, when many systems block ICMP yet still respond on TCP ports.

25
MCQeasy

During external reconnaissance you collect DNS records for a target organization and find an MX record pointing to mail.example.com. You want to identify the IP addresses of other hosts in the same mail infrastructure without sending any packets directly to the target's servers. Which action best fits this passive goal?

A.Query a public passive DNS database such as SecurityTrails or VirusTotal for historical A records of example.com.
B.Use nmap -sn 203.0.113.0/24 to discover which hosts in the mail subnet are alive.
C.Run dig axfr @ns1.example.com example.com to transfer the full zone.
D.Perform a reverse DNS lookup against each IP in the target's announced BGP prefixes.
AnswerA

Passive DNS databases store historical resolution data collected from recursive resolvers and other sensors, so querying them reveals IP addresses and subdomains without any packet ever reaching the target's infrastructure. That directly satisfies the requirement to identify hosts while remaining passive. Historical records can also expose decommissioned or origin hosts that current DNS no longer advertises, adding reconnaissance value.

Why this answer

Passive reconnaissance relies on data already collected by third parties, so no packets touch the target. Passive DNS services aggregate historical resolution records from many sensors, letting you map subdomains and IP addresses, including hosts no longer published. Zone transfers, ping sweeps, and reverse lookups all generate traffic toward the target or its authoritative infrastructure, which breaks the passive-only requirement stated in the scenario.

Exam trap

The trap here is assuming that any DNS query is passive, when queries sent to the target's own name servers or hosts are active and attributable.

26
MCQmedium

During an internal assessment you run a TCP SYN scan and note that a host responds with an RST/ACK for every probed port. What does this behavior most reliably indicate about the target host?

A.The host is up and reachable, but no TCP listeners are present on the probed ports.
B.The target is running an IDS that spoofs resets to mislead the scanner.
C.The probed ports are open but the services are refusing the connection.
D.A stateful firewall is silently dropping the probe packets before they reach the host.
AnswerA

An RST/ACK reply to a SYN means the host's TCP stack is alive and actively rejecting the connection because no process is bound to that port. This is the canonical 'closed port' response and confirms host reachability, which is why filtered versus closed distinctions matter so much during enumeration.

Why this answer

A TCP RST/ACK in response to a SYN is the standard signal of a closed but reachable port, because the kernel answers on behalf of a port with no bound listener. It confirms the host is alive and the path is unfiltered, letting you distinguish closed ports from filtered ones and focus subsequent service enumeration on ports that actually return SYN/ACK.

Exam trap

The trap here is assuming any reply means the port is open, when a reset confirms the opposite: the host is alive but nothing is listening.

27
MCQeasy

Which command-line tool is primarily used during the reconnaissance phase to identify open ports and service versions on a remote target?

A.netcat
B.Nmap
C.Wireshark
D.grep
AnswerB

Nmap is the primary utility for network discovery and security auditing. It offers advanced features like service version detection, operating system fingerprinting, and scriptable automation, making it the most reliable and comprehensive tool available for identifying the services running on a target during the reconnaissance phase of testing.

Why this answer

Nmap is the industry-standard tool for port scanning and service enumeration. By identifying open ports and the software versions running on them, a tester can pinpoint specific vulnerabilities to research. This step is the foundation of the reconnaissance phase, as it maps the target's attack surface and guides the subsequent selection of exploits, ensuring a focused and efficient penetration testing process.

Exam trap

Candidates often confuse Nmap with vulnerability scanners like Nessus or OpenVAS. While Nmap can run scripts, its primary role is port scanning, service detection, and reconnaissance.

28
MCQeasy

During a penetration test, you need to enumerate DNS records for the domain `example.com` to find subdomains and mail servers. Which command should you use to perform a zone transfer attempt?

A.`nslookup -type=any example.com`
B.`host -l example.com ns1.example.com`
C.`dnsenum --enum example.com`
D.`dig axfr @ns1.example.com example.com`
AnswerD

The `axfr` option in `dig` requests a full zone transfer from the specified name server. If the server is misconfigured to allow transfers from any host, it will return all DNS records for the domain, revealing subdomains, mail servers, and other hosts. This is the standard command for attempting a zone transfer.

Why this answer

The `dig axfr` command is the direct way to request a zone transfer from a name server. It targets the specific DNS server and domain, and if the server allows transfers, it returns the full zone file. Other commands may perform DNS queries but do not explicitly request a zone transfer.

Exam trap

The trap here is confusing general DNS enumeration tools with the specific AXFR query needed for a zone transfer attempt.

29
MCQmedium

You are performing a network scan on a target network and notice that ICMP echo requests are blocked, but you need to determine if the target host is alive. Which technique should you utilize to identify active hosts without relying on standard ICMP ping?

A.Send a UDP packet to port 53 and wait for a DNS response.
B.Perform a TCP SYN scan on common ports such as 80, 443, and 22.
C.Use ARP scanning regardless of the network topography.
D.Send a broadcast ping to the entire subnet range.
AnswerB

TCP SYN scanning to common ports reliably confirms host activity by triggering a response from the TCP/IP stack. Since most servers run these services, the receipt of a SYN/ACK or RST packet acts as a definitive indicator that the host is reachable, bypassing the need for ICMP connectivity.

Why this answer

When ICMP is filtered by firewalls, TCP SYN scanning on common ports like 80 or 443 is an effective alternative for host discovery. This technique works because the target system responds to a SYN packet with a SYN/ACK if the port is open, or an RST if closed, confirming the host's presence. Mastering non-ICMP discovery is critical for bypass techniques in hardened network environments where security policies block traditional discovery methods.

Exam trap

Candidates often assume that if ICMP ping fails, the target host is completely dead and abandon further testing, forgetting that firewalls frequently block ICMP echo requests.

30
MCQmedium

You have identified an open port 445 on a Windows machine. Which tool is most effective for checking if the machine is vulnerable to common SMB-based exploits like EternalBlue?

A.Use ping to verify the host is reachable.
B.Use Nmap with the --script smb-vuln-ms17-010 argument.
C.Run a full Nessus scan against the IP.
D.Use telnet to manually send an exploit string.
AnswerB

The Nmap NSE script smb-vuln-ms17-010 is specifically written to detect the EternalBlue vulnerability. It performs a safe check by interacting with the SMB service to see if it responds in a way that indicates the vulnerability, providing a fast and accurate assessment during the reconnaissance phase of the test.

Why this answer

Nmap's scripting engine (NSE) is the most effective way to check for specific vulnerabilities like EternalBlue without requiring a full-scale vulnerability scanner. The 'smb-vuln-ms17-010' script is specifically designed to detect this vulnerability. Using such targeted scripts allows for accurate assessment with minimal footprint, which is a hallmark of professional penetration testing practices, ensuring the system's security posture is evaluated safely and effectively during the reconnaissance phase.

Exam trap

Candidates often suggest using Nessus or OpenVAS, which are full-scale scanners. The question specifically asks for a tool to check for a single exploit, making targeted Nmap scripts the preferred answer.

31
Multi-Selectmedium

You need to fingerprint the web server technology behind an HTTP service without sending malformed or intrusive requests. Which two actions best accomplish passive-leaning banner and behavior fingerprinting during enumeration? (Choose two.)

Select 2 answers
A.Send a buffer of several thousand bytes in the request line to provoke a crash signature.
B.Inspect the Server and X-Powered-By response headers returned in the HTTP reply.
C.Request a deliberately nonexistent path and analyze the structure of the resulting error page.
D.Run a full TCP port scan of all 65535 ports on the host to infer the web stack.
E.Attempt default administrative credentials against the web login form.
AnswersB, C

Response headers often disclose the web server software, version, and backend language runtime. Reading them requires only a normal request, so it is low-risk and directly identifies the technology stack. This makes header inspection a foundational, non-intrusive fingerprinting step that frequently narrows the target's platform before deeper probing.

Why this answer

Header inspection and error-page analysis both identify server technology using ordinary, non-destructive requests. Headers may name the server and runtime directly, while distinctive 404 templates expose the stack when banners are hidden. Together they fingerprint the web service safely, whereas crash attempts, full port sweeps, and credential guessing are intrusive or simply unrelated to identifying the technology.

Exam trap

The trap here is equating aggressive probing such as crash attempts or credential guessing with fingerprinting, when simple headers and error pages already reveal the stack.

32
MCQmedium

You are enumerating an Apache web server and discover the '.git' directory is accessible. What is the most significant risk this poses for your reconnaissance?

A.It indicates the server is using an outdated version of Apache.
B.The entire source code repository can be downloaded.
C.It means the server is vulnerable to SQL injection.
D.It suggests that the server is running on a Windows OS.
AnswerB

Exposed .git directories allow an attacker to reconstruct the entire project repository, including code, database schema, and configuration files. This provides deep insight into the application's internal structure and security logic, exposing credentials or secrets that are frequently hardcoded by developers during the initial phases of coding.

Why this answer

An exposed '.git' directory allows an attacker to download the entire project repository, including source code, configuration files, and commit history. This is a critical discovery because the source code may contain hardcoded credentials, API keys, or sensitive business logic that would otherwise be hidden. Analyzing this data often provides the most direct path to exploitation, as it reveals the application's internal workings and potential flaws that are not apparent from the outside.

Exam trap

Candidates often assume the risk is just file disclosure or directory listing. The most significant risk is the full repository download, which provides the entire codebase and sensitive history.

33
MCQhard

You are enumerating a Windows host and have obtained valid low-privilege domain credentials. You want to identify which systems in the domain the account can access administratively, so you can plan lateral movement. Which approach most efficiently maps that access?

A.Use CrackMapExec or NetExec with the credentials to test administrative access across the domain.
B.Query the domain controller with ldapsearch for all computer objects and their operating systems.
C.Capture network traffic on the domain controller to observe authentication events.
D.Run a full TCP port scan of every host in the domain to find open port 445.
AnswerA

Tools like CrackMapExec and NetExec authenticate to each host using the supplied credentials and report whether the account has administrative rights, often by attempting a privileged operation such as reading the SAM database or listing shares with admin access. That directly answers which systems the account can control. Running it against the domain inventory is far more efficient and informative than scanning for open ports, because it tests actual authorization rather than mere reachability.

Why this answer

Mapping administrative access requires testing authorization, not just reachability or inventory. Credentialed tools such as CrackMapExec and NetExec authenticate to each host and report whether the supplied account holds administrative rights, typically by performing a privileged action. Port scans only show that SMB is listening, directory queries only list computers, and packet capture observes rather than tests, so none of those alternatives directly answers where the low-privilege account can move laterally.

Exam trap

The trap here is equating an open SMB port with administrative access, when authorization must be tested with the actual credentials.

Ready to test yourself?

Try a timed practice session using only Enumeration And Reconnaissance questions.