Courseiva

PEN-200 Enumeration and Reconnaissance Practice Question

You are conducting a penetration test and need to identify the operating system of a target host without sending any packets to it. Which of the following methods is most appropriate?

⚠ Common exam trap

The trap here is assuming that analyzing TTL values is passive because it uses ping responses, but it still requires sending packets to the target.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reviewing publicly available information such as job postings or technology stack details on the company's website.

Passive reconnaissance involves gathering information without directly interacting with the target. Reviewing public sources like job postings and website technology stacks can reveal the operating system without sending any packets. Active methods such as TTL analysis, Nmap OS detection, and banner grabbing all require sending packets to the target, violating the constraint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Reviewing publicly available information such as job postings or technology stack details on the company's website.

    Why this is correct

    Reviewing publicly available information is a passive reconnaissance technique that does not involve any direct interaction with the target. Job postings might mention specific operating systems or technologies, and the website's technology stack can be inferred from headers or public profiles. This meets the requirement of sending no packets to the target.

  • ✗

    Analyzing the Time-to-Live (TTL) values from a ping response.

    Why it's wrong here

    Analyzing TTL values requires sending packets (e.g., ICMP echo requests) to the target and observing the responses. This is an active technique because it directly interacts with the target. The requirement is to avoid sending any packets, so this method is not appropriate.

  • ✗

    Using Nmap's OS detection (-O) against the target IP address.

    Why it's wrong here

    Nmap's OS detection sends a series of crafted packets to the target and analyzes the responses to guess the operating system. This is an active technique because it directly probes the target. Since the scenario requires no packets be sent, this method is not suitable.

  • ✗

    Performing a banner grab by connecting to open ports like 22 or 80.

    Why it's wrong here

    Banner grabbing involves establishing a connection to a service on the target and reading its response. This sends packets to the target and is therefore an active technique. The requirement explicitly states no packets should be sent, so this is not appropriate.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.