Courseiva

PEN-200 Enumeration and Reconnaissance Practice Question

You have identified an open port 445 on a Windows machine. Which tool is most effective for checking if the machine is vulnerable to common SMB-based exploits like EternalBlue?

⚠ Common exam trap

Candidates often suggest using Nessus or OpenVAS, which are full-scale scanners. The question specifically asks for a tool to check for a single exploit, making targeted Nmap scripts the preferred answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Nmap with the --script smb-vuln-ms17-010 argument.

Nmap's scripting engine (NSE) is the most effective way to check for specific vulnerabilities like EternalBlue without requiring a full-scale vulnerability scanner. The 'smb-vuln-ms17-010' script is specifically designed to detect this vulnerability. Using such targeted scripts allows for accurate assessment with minimal footprint, which is a hallmark of professional penetration testing practices, ensuring the system's security posture is evaluated safely and effectively during the reconnaissance phase.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use ping to verify the host is reachable.

    Why it's wrong here

    Ping only confirms connectivity and provides no information regarding service versions or vulnerabilities. Using it to assess for SMB exploits is useless, as it cannot interact with the SMB protocol or perform any kind of vulnerability detection, making it an inappropriate tool for this specific technical requirement.

  • ✓

    Use Nmap with the --script smb-vuln-ms17-010 argument.

    Why this is correct

    The Nmap NSE script smb-vuln-ms17-010 is specifically written to detect the EternalBlue vulnerability. It performs a safe check by interacting with the SMB service to see if it responds in a way that indicates the vulnerability, providing a fast and accurate assessment during the reconnaissance phase of the test.

  • ✗

    Run a full Nessus scan against the IP.

    Why it's wrong here

    While Nessus is a powerful scanner, running a full scan is often too noisy and against the methodology of a focused manual penetration test. Using targeted scripts is preferred to reduce the risk of crashing the target system and to maintain a more controlled and surgical testing environment.

  • ✗

    Use telnet to manually send an exploit string.

    Why it's wrong here

    Telnet is not suitable for sending complex binary exploit strings for SMB vulnerabilities. Attempting this manually is prone to error, highly unlikely to succeed, and lacks the precision required for testing specific vulnerabilities. Using specialized tools like Nmap scripts or Metasploit modules is the correct, professional approach.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.