Courseiva

PEN-200 · topic practice

Enumeration and Reconnaissance practice questions

This domain covers active and passive information gathering before exploitation: host discovery, port and service scanning with Nmap, DNS and infrastructure enumeration, and interpreting scan responses correctly. PEN-200 tests it through scenario questions where you must choose the right scan type or tool and infer host state from ICMP, TCP, and RST/ACK behavior.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Enumeration and Reconnaissance

What the exam tests

What to know about Enumeration and Reconnaissance

You must be able to run and read Nmap scans, interpret ICMP and TCP responses, and enumerate DNS and services to build a target picture. The single most important skill is correctly distinguishing open, closed, and filtered states and what each reveals about the target's firewall and host status.

Interpreting Nmap port states (open, closed, filtered) and what each implies about firewalls

Choosing scan types such as TCP SYN, connect, UDP, and ICMP echo for a given target

Enumerating DNS records (A, MX, NS, TXT) and mapping mail or name infrastructure

Using Nmap service/version detection and tools like nslookup, dig, and whois

Watch out for

Common Enumeration and Reconnaissance exam traps

  • ▸Assuming filtered ports mean the host is down, when a firewall may simply be dropping probes
  • ▸Confusing RST/ACK replies (closed port) with no response (filtered) during SYN scans
  • ▸Treating MX records as direct mail server IPs instead of resolving the hostname first

Practice set

Enumeration and Reconnaissance questions

20 questions · select your answer, then reveal the explanation

You are enumerating a target and find a service on port 3389. What is the most effective way to identify if this service is open to remote login attacks during the reconnaissance phase?

Refer to the exhibit. Given the information discovered, what is the most logical immediate next step in the enumeration process?

Exhibit

C:\> dir /s /b C:\ | findstr /i "config.php"
C:\inetpub\wwwroot\app\config.php
C:\inetpub\wwwroot\app\includes\config.php.bak

C:\> type C:\inetpub\wwwroot\app\includes\config.php.bak
<?php
$db_user = 'root';
$db_pass = 'P@ssw0rd123!';
$db_host = 'localhost';
?>

You are conducting internal enumeration against a Windows host. Running `nmap -sU -p 161 --script snmp-brute <target>` fails to produce any output, but you know the host is running an SNMP service. Which command should you run next to retrieve basic system information from this host?

During a penetration test, you run a UDP scan against a target and see that port 161 is open. You then run `snmpwalk -v2c -c public 192.168.1.50`. The command returns a large amount of system information, including running processes and installed software. What is the most likely reason this enumeration succeeded?

You are enumerating a web server and discover that directory listing is enabled on `/backup/`. Browsing it reveals a file named `db_dump.sql.bz2`. You download it, decompress it, and find a `users` table containing password hashes in the format `$2y$10$...`. What is the most appropriate next step to further your access?

You are performing a penetration test against a Windows domain. You have obtained a low-privileged domain user's credentials. You want to enumerate all computers in the domain to identify potential targets. Which command is most appropriate to achieve this using built-in Windows tools?

You are performing active reconnaissance against a target network and want to identify live hosts without triggering IDS alerts. Which two techniques are most appropriate for this goal? (Choose two.)

You are enumerating a Windows host and discover that port 139 is open, but port 445 is closed. You want to list the available SMB shares. Which command should you use?

You are performing a network scan on a target network and notice that ICMP echo requests are blocked, but you need to determine if the target host is alive. Which technique should you utilize to identify active hosts without relying on standard ICMP ping?

Refer to the exhibit. You have scanned a target and obtained these results. Which step is most logical to perform next to effectively enumerate the web service?

Exhibit

PORT   STATE SERVICE
21/tcp open  ftp
22/tcp open  ssh
80/tcp open  http

Which TWO of the following techniques are most effective for enumerating SMB shares on a Windows host during a penetration test?

Which command-line tool is primarily used during the reconnaissance phase to identify open ports and service versions on a remote target?

When enumerating a web application, which THREE of the following items are most important to identify to increase the likelihood of finding a vulnerability?

During a network assessment, you want to enumerate users on a domain controller. Which protocol and port combination is the most standard target for this type of enumeration?

Refer to the exhibit. Based on the HTTP response headers provided, what critical information can be gathered for your reconnaissance?

Exhibit

HTTP/1.1 200 OK
Server: Apache/2.4.41 (Ubuntu)
Content-Type: text/html; charset=UTF-8
X-Powered-By: PHP/7.4.3

When performing reconnaissance on an unknown network, you discover a service running on port 161. What is the most appropriate action to take to determine if this service can be abused?

You have identified an open port 445 on a Windows machine. Which tool is most effective for checking if the machine is vulnerable to common SMB-based exploits like EternalBlue?

Which TWO of the following actions are considered best practice during the initial host enumeration phase to avoid detection by security monitoring tools?

You are enumerating an Apache web server and discover the '.git' directory is accessible. What is the most significant risk this poses for your reconnaissance?

Refer to the exhibit. Which ports are currently open on the target host 192.168.1.10?

Exhibit

Starting Nmap 7.91 ( https://nmap.org ) at 2023-10-27 10:00 UTC
Nmap scan report for 192.168.1.10
Host is up (0.001s latency).
Not shown: 998 closed ports
PORT    STATE SERVICE
22/tcp  open  ssh
80/tcp  open  http

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Enumeration and Reconnaissance sessions

Start a Enumeration and Reconnaissance only practice session

Every question in these sessions is drawn from the Enumeration and Reconnaissance domain — nothing else.

Related practice questions

Related PEN-200 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PEN-200 exam test about Enumeration and Reconnaissance?
You must be able to run and read Nmap scans, interpret ICMP and TCP responses, and enumerate DNS and services to build a target picture. The single most important skill is correctly distinguishing open, closed, and filtered states and what each reveals about the target's firewall and host status.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Enumeration and Reconnaissance questions in a focused session?
Yes — the session launcher on this page draws every question from the Enumeration and Reconnaissance domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PEN-200 topics?
Use the topic links above to move to related areas, or go back to the PEN-200 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PEN-200 exam covers. They are not copied from any real exam or dump site.