PEN-200 Enumeration and Reconnaissance Practice Question
You are enumerating a Linux target and discover that TCP port 2049 is open. You run `showmount -e 192.168.1.100` and see that the `/home` directory is exported to everyone. What is the most significant security risk this configuration presents?
⚠ Common exam trap
The trap here is focusing on potential software vulnerabilities or DoS when the real issue is the misconfigured export that grants unauthenticated access to sensitive user data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An attacker can mount the share and read or modify any user's home directory files, potentially leading to privilege escalation.
An NFS export to everyone allows any attacker to mount the share without authentication, gaining read and write access to the /home directory. This can lead to theft of SSH keys, modification of scripts, or insertion of malicious code, ultimately enabling privilege escalation or lateral movement. The other options either describe unrelated vulnerabilities or less severe impacts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The NFS service is vulnerable to a buffer overflow that allows remote code execution.
Why it's wrong here
While NFS implementations may have vulnerabilities, the scenario describes a misconfiguration (export to everyone) rather than a specific software vulnerability. The primary risk here is unauthorized access due to weak export permissions, not a buffer overflow. Assuming a buffer overflow without evidence is speculative.
- ✗
An attacker can use the NFS share to perform a denial-of-service attack by filling the disk.
Why it's wrong here
A denial-of-service by filling the disk is possible if the share is writable, but it is not the most significant risk. The ability to read and modify user files, including SSH keys and sensitive data, poses a much greater threat because it can lead to full system compromise. The question asks for the most significant risk.
- ✗
The NFS share allows anonymous FTP access to the same directory.
Why it's wrong here
NFS and FTP are separate protocols. An NFS export does not imply that FTP is running or that it shares the same directory. This option incorrectly conflates two different services. The presence of NFS on port 2049 does not indicate anything about FTP.
- ✓
An attacker can mount the share and read or modify any user's home directory files, potentially leading to privilege escalation.
Why this is correct
When NFS exports a directory to everyone (i.e., world-readable and writable), any remote attacker can mount it without authentication. This grants access to all files within /home, including sensitive data like SSH keys, configuration files, and scripts. If writable, an attacker could inject malicious code or modify authorized_keys to escalate privileges.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.