Courseiva

PEN-200 Enumeration and Reconnaissance Practice Question

You are enumerating a Linux host and discover TCP port 2049 open. You need to determine what is being exported and to whom before deciding on any exploitation path. Which action most directly answers that question?

⚠ Common exam trap

The trap here is treating any open file-sharing port as SMB and reaching for smbclient instead of matching the tool to the NFS service on port 2049.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run showmount -e <target> to list exported filesystems and permitted clients.

NFS enumeration centers on the mount protocol, which advertises exported directories and the client hosts or networks authorized to mount them. The showmount utility with the -e flag performs exactly that query against the target. Other tools suggested here speak SMB, RDP, or FTP, none of which correspond to the NFS service listening on port 2049, so they cannot reveal export details or access restrictions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Run showmount -e <target> to list exported filesystems and permitted clients.

    Why this is correct

    Port 2049 is NFS, and showmount -e queries the target's mount daemon to display each exported share along with the host or subnet allowed to mount it. That output directly answers what is exported and to whom, which is exactly the reconnaissance objective. It is a lightweight, standard query that does not modify anything on the server, making it the most direct and appropriate next step.

  • ✗

    Run smbclient -L //<target> -N to list available SMB shares.

    Why it's wrong here

    smbclient speaks SMB, which is a Windows file-sharing protocol typically on ports 139 and 445, not the NFS service on 2049. Pointing it at an NFS server will simply fail or return nothing useful. It does not reveal NFS exports or client restrictions, so it cannot answer the question posed by the open port, making it a protocol mismatch for this scenario.

  • ✗

    Use ftp <target> 2049 and authenticate anonymously to browse the share.

    Why it's wrong here

    FTP servers conventionally listen on port 21, and while a service could theoretically be moved, port 2049 is the registered NFS port. An FTP client cannot speak the ONC RPC protocol NFS uses, so the session would fail during negotiation. Even if anonymous FTP were available elsewhere, it would not enumerate NFS exports or the clients permitted to mount them.

  • ✗

    Connect with rdesktop <target>:2049 to inspect the remote desktop session.

    Why it's wrong here

    rdesktop implements the RDP client protocol, which normally runs on port 3389, not 2049. NFS does not provide an interactive desktop, so this connection attempt would not succeed in any meaningful way. Choosing this option confuses two unrelated remote-access services and provides no information about NFS exports or the access control list attached to them.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.