Courseiva

PEN-200 Enumeration and Reconnaissance Practice Question

You are enumerating a Linux target and discover that TCP port 2049 is open. You run `showmount -e 192.168.1.100` and see that the `/home` directory is exported to everyone. What is the most significant security risk this configuration presents?

⚠ Common exam trap

The trap here is focusing on potential software vulnerabilities or DoS when the real issue is the misconfigured export that grants unauthenticated access to sensitive user data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An attacker can mount the share and read or modify any user's home directory files, potentially leading to privilege escalation.

An NFS export to everyone allows any attacker to mount the share without authentication, gaining read and write access to the /home directory. This can lead to theft of SSH keys, modification of scripts, or insertion of malicious code, ultimately enabling privilege escalation or lateral movement. The other options either describe unrelated vulnerabilities or less severe impacts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The NFS service is vulnerable to a buffer overflow that allows remote code execution.

    Why it's wrong here

    While NFS implementations may have vulnerabilities, the scenario describes a misconfiguration (export to everyone) rather than a specific software vulnerability. The primary risk here is unauthorized access due to weak export permissions, not a buffer overflow. Assuming a buffer overflow without evidence is speculative.

  • ✗

    An attacker can use the NFS share to perform a denial-of-service attack by filling the disk.

    Why it's wrong here

    A denial-of-service by filling the disk is possible if the share is writable, but it is not the most significant risk. The ability to read and modify user files, including SSH keys and sensitive data, poses a much greater threat because it can lead to full system compromise. The question asks for the most significant risk.

  • ✗

    The NFS share allows anonymous FTP access to the same directory.

    Why it's wrong here

    NFS and FTP are separate protocols. An NFS export does not imply that FTP is running or that it shares the same directory. This option incorrectly conflates two different services. The presence of NFS on port 2049 does not indicate anything about FTP.

  • ✓

    An attacker can mount the share and read or modify any user's home directory files, potentially leading to privilege escalation.

    Why this is correct

    When NFS exports a directory to everyone (i.e., world-readable and writable), any remote attacker can mount it without authentication. This grants access to all files within /home, including sensitive data like SSH keys, configuration files, and scripts. If writable, an attacker could inject malicious code or modify authorized_keys to escalate privileges.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.