PEN-200 Enumeration and Reconnaissance Practice Question
You are enumerating a Linux host and discover TCP port 2049 open. You need to determine what is being exported and to whom before deciding on any exploitation path. Which action most directly answers that question?
⚠ Common exam trap
The trap here is treating any open file-sharing port as SMB and reaching for smbclient instead of matching the tool to the NFS service on port 2049.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run showmount -e <target> to list exported filesystems and permitted clients.
NFS enumeration centers on the mount protocol, which advertises exported directories and the client hosts or networks authorized to mount them. The showmount utility with the -e flag performs exactly that query against the target. Other tools suggested here speak SMB, RDP, or FTP, none of which correspond to the NFS service listening on port 2049, so they cannot reveal export details or access restrictions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Run showmount -e <target> to list exported filesystems and permitted clients.
Why this is correct
Port 2049 is NFS, and showmount -e queries the target's mount daemon to display each exported share along with the host or subnet allowed to mount it. That output directly answers what is exported and to whom, which is exactly the reconnaissance objective. It is a lightweight, standard query that does not modify anything on the server, making it the most direct and appropriate next step.
- ✗
Run smbclient -L //<target> -N to list available SMB shares.
Why it's wrong here
smbclient speaks SMB, which is a Windows file-sharing protocol typically on ports 139 and 445, not the NFS service on 2049. Pointing it at an NFS server will simply fail or return nothing useful. It does not reveal NFS exports or client restrictions, so it cannot answer the question posed by the open port, making it a protocol mismatch for this scenario.
- ✗
Use ftp <target> 2049 and authenticate anonymously to browse the share.
Why it's wrong here
FTP servers conventionally listen on port 21, and while a service could theoretically be moved, port 2049 is the registered NFS port. An FTP client cannot speak the ONC RPC protocol NFS uses, so the session would fail during negotiation. Even if anonymous FTP were available elsewhere, it would not enumerate NFS exports or the clients permitted to mount them.
- ✗
Connect with rdesktop <target>:2049 to inspect the remote desktop session.
Why it's wrong here
rdesktop implements the RDP client protocol, which normally runs on port 3389, not 2049. NFS does not provide an interactive desktop, so this connection attempt would not succeed in any meaningful way. Choosing this option confuses two unrelated remote-access services and provides no information about NFS exports or the access control list attached to them.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.