Courseiva

PEN-200 Enumeration and Reconnaissance Practice Question

Which TWO of the following techniques are most effective for enumerating SMB shares on a Windows host during a penetration test?

⚠ Common exam trap

Candidates often forget specific syntax parameters or use tools that require active domain credentials when attempting unauthenticated SMB enumeration like null sessions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use smbclient -L //target_ip -N to list available shares.

Enumerating SMB shares is crucial for identifying sensitive data, configuration files, or scripts that can lead to privilege escalation. Tools like smbclient and specialized scripts allow testers to interact with the SMB protocol to list shares and check for null sessions. Understanding these methods is fundamental for gathering intelligence in Windows environments, as misconfigured SMB permissions often provide an easy path to sensitive information and potential system compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use smbclient -L //target_ip -N to list available shares.

    Why this is correct

    The smbclient tool is the standard Linux utility for interacting with SMB shares. The -L flag queries the target for a list of shares, and the -N flag specifies no password, which is essential when testing for null sessions or guest access that might be improperly enabled on the target.

  • ✓

    Run nmap with the --script smb-enum-shares scan argument.

    Why this is correct

    The Nmap NSE script library includes powerful modules specifically designed for SMB enumeration. Using smb-enum-shares allows you to automate the process of discovering shares and their associated access permissions, providing a comprehensive view of the filesystem without requiring individual manual connections to each potential share folder.

  • ✗

    Perform a brute-force attack on the C$ share.

    Why it's wrong here

    Brute-forcing administrative shares is aggressive and likely to trigger account lockout policies or security alerts. Administrative shares usually require high-level privileges, and attempting to guess credentials for them is inefficient compared to identifying misconfigured shares that allow anonymous or guest read access, which is a common vulnerability.

  • ✗

    Attempt to ping the host using ICMP to check SMB connectivity.

    Why it's wrong here

    Pinging a host only confirms that the network path is open and the host is active; it provides zero information regarding SMB share availability or configuration. This step is unrelated to the specific goal of enumerating SMB shares and does not contribute to gathering the required filesystem intelligence.

  • ✗

    Use the telnet command to connect to port 445.

    Why it's wrong here

    Telnet is designed for interactive text communication and is incapable of performing the complex SMB handshake required to list shares. While it can confirm that the port is open, it cannot provide the functional data necessary to enumerate the actual file structure or permissions of the SMB environment.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.