PEN-200 Enumeration and Reconnaissance Practice Question
Which TWO of the following actions are considered best practice during the initial host enumeration phase to avoid detection by security monitoring tools?
⚠ Common exam trap
Candidates often include aggressive scanning techniques like 'full TCP connect scans'. The question asks for best practices to 'avoid detection', which mandates passive methods and rate-limited active traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Prioritize passive reconnaissance using OSINT sources.
To minimize detection, penetration testers should prioritize passive information gathering before engaging in active, noisy scanning. When active scanning is required, rate-limiting and targeting specific ports rather than performing a 'scan all' approach helps blend the traffic into normal network behavior. These practices are essential for maintaining the stealth required in professional engagements, ensuring that the tester remains undetected while collecting the necessary intelligence to identify high-value targets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform a full port scan on all 65535 ports concurrently.
Why it's wrong here
Scanning all ports concurrently generates a massive spike in network traffic, which is a primary indicator for IDS/IPS systems. This is extremely noisy and will almost certainly alert the target's security team, violating the principle of stealth and potentially leading to the tester's IP being blacklisted early on.
- ✓
Prioritize passive reconnaissance using OSINT sources.
Why this is correct
Passive reconnaissance involves gathering information without directly interacting with the target, such as using search engines, public records, or WHOIS data. This is completely stealthy, as it leaves no trace on the target system or their network, making it an essential first step in any professional engagement.
- ✓
Implement scan rate-limiting to reduce traffic volume.
Why this is correct
Rate-limiting the frequency of probes significantly reduces the likelihood of triggering anomaly-based detection systems. By slowing down the scan, the tester mimics more natural traffic patterns, which allows for consistent data collection while significantly lowering the chances of being blocked by security devices monitoring for rapid scanning behavior.
- ✗
Use aggressive service detection flags in all scans.
Why it's wrong here
Aggressive service detection flags force the scanner to perform deep probes and multiple handshake attempts, creating highly unusual traffic patterns that are easily flagged by security analysts. This behavior is the opposite of stealth and should only be used when necessary and with full authorization for a noisy test.
- ✗
Scan from the same IP address at all times.
Why it's wrong here
Consistently scanning from the same IP address makes it trivial for security teams to identify and block the source. While sometimes required by the scope, failing to vary techniques or utilize proxying when allowed decreases the chance of long-term success during a multi-day or multi-week penetration testing engagement.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.