PEN-200 Enumeration and Reconnaissance Practice Question
You have successfully identified a Windows target and need to perform deep enumeration. Which TWO techniques are most effective for identifying hidden local services and internal network connections?
⚠ Common exam trap
Candidates rely solely on external port scans and completely forget to run internal OS-level enumeration commands to find hidden local-only services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Execute 'netstat -ano' to identify local listening ports and associated process IDs.
Enumerating internal connections and services is essential for identifying lateral movement paths or local-only management interfaces. Using netstat confirms listening sockets that may not be exposed to the external network. Simultaneously, querying the Service Control Manager allows for the discovery of non-standard or custom services that might not be detected by typical port scans. Mastering these OS-specific enumeration techniques significantly increases the likelihood of finding vulnerabilities in non-obvious entry points.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Execute 'netstat -ano' to identify local listening ports and associated process IDs.
Why this is correct
The 'netstat -ano' command provides a comprehensive view of all active network connections and listening ports, including the specific process IDs (PIDs) associated with them. This is a foundational step in identifying locally bound services that are not accessible from the external network but are reachable via local exploitation.
- ✗
Run 'nmap -sS -p- 127.0.0.1' from the target machine to map all possible services.
Why it's wrong here
While scanning localhost can reveal services, using Nmap on the target machine is 'noisy' and can trigger signature-based antivirus or EDR solutions. Native Windows binaries like 'netstat' or 'tasklist' are preferred because they are pre-installed, stealthier, and do not require introducing external tools that could be flagged by security software.
- ✓
Use 'wmic service get name,displayname,state,startmode' to list all configured services.
Why this is correct
WMIC is a powerful built-in tool that allows for structured querying of the Windows Service Control Manager. Listing services by name, state, and start mode helps identify unauthorized or vulnerable background processes that could be exploited for privilege escalation or persistence, even if they are not actively listening on a port.
- ✗
Analyze the 'hosts' file to find hidden DNS records for internal applications.
Why it's wrong here
The 'hosts' file is used for local name resolution, not for discovering services or open network ports. While it might reveal internal hostnames or aliases, it does not provide information about active listening services or the state of the network stack, making it ineffective for the requested enumeration goals.
- ✗
Check the system event logs for recent login attempts by administrative users.
Why it's wrong here
Event logs are valuable for auditing and forensics, but they do not provide real-time information about currently listening network services or internal port bindings. Enumerating current state requires tools that query the network stack or process manager, rather than tools that look at historical authentication logs.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.