Courseiva

PEN-200 Enumeration and Reconnaissance Practice Question

You are enumerating a Linux host and find that UDP port 161 responds to SNMP queries with the community string 'public'. Which action yields the most useful reconnaissance data for planning later exploitation?

⚠ Common exam trap

The trap here is treating an SNMP community string as a reusable credential for other services instead of a read key for the MIB.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run snmpwalk against the device to dump the MIB tree and extract system and interface information.

A working SNMP community string grants read access to the Management Information Base, and snmpwalk systematically dumps that tree. The resulting system descriptions, interface listings, and routing data give concrete enumeration value, exposing OS details and network layout that guide subsequent exploitation far better than any write, authentication, or trap-based approach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Run snmpwalk against the device to dump the MIB tree and extract system and interface information.

    Why this is correct

    With a valid read-only community string, snmpwalk traverses the Management Information Base and returns system description, interfaces, routing tables, and sometimes process or user data. This structured output directly feeds later phases by revealing OS versions, network topology, and potential pivot points, making it the highest-value follow-up action here.

  • ✗

    Send SNMP traps to the device to force it to report its running configuration.

    Why it's wrong here

    Traps are unsolicited notifications the agent sends to a manager, not a request mechanism. A client cannot cause the agent to emit a configuration dump by sending traps, and devices typically ignore inbound trap traffic. Querying the agent with a valid community string is the correct way to pull data from the MIB.

  • ✗

    Use the community string to authenticate to the device over SSH on port 22.

    Why it's wrong here

    SNMP community strings are not credentials for SSH or any other login service; they only authorize SNMP operations. Trying to reuse 'public' as an SSH password fails and may lock accounts. The protocol boundary means SNMP access must be exploited through SNMP itself, not repurposed as an authentication token elsewhere.

  • ✗

    Attempt an SNMP write operation using the same community string to alter device configuration.

    Why it's wrong here

    The 'public' string is conventionally read-only, so write attempts will be rejected and may trigger logging. Even if a writable string existed, blindly modifying configuration is destructive and outside the enumeration goal. Reading the MIB first is both safer and more informative than attempting writes during reconnaissance.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.