PEN-200 Enumeration and Reconnaissance Practice Question
You need to fingerprint the web server technology behind an HTTP service without sending malformed or intrusive requests. Which two actions best accomplish passive-leaning banner and behavior fingerprinting during enumeration? (Choose two.)
⚠ Common exam trap
The trap here is equating aggressive probing such as crash attempts or credential guessing with fingerprinting, when simple headers and error pages already reveal the stack.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Inspect the Server and X-Powered-By response headers returned in the HTTP reply.
Header inspection and error-page analysis both identify server technology using ordinary, non-destructive requests. Headers may name the server and runtime directly, while distinctive 404 templates expose the stack when banners are hidden. Together they fingerprint the web service safely, whereas crash attempts, full port sweeps, and credential guessing are intrusive or simply unrelated to identifying the technology.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Send a buffer of several thousand bytes in the request line to provoke a crash signature.
Why it's wrong here
Oversized request lines are an intrusive test that can crash or destabilize the service. Enumeration should avoid actions that risk availability or trigger alerts. Fingerprinting can be achieved safely through headers and error pages, so injecting malformed input is unnecessary and counterproductive during the reconnaissance phase.
- ✓
Inspect the Server and X-Powered-By response headers returned in the HTTP reply.
Why this is correct
Response headers often disclose the web server software, version, and backend language runtime. Reading them requires only a normal request, so it is low-risk and directly identifies the technology stack. This makes header inspection a foundational, non-intrusive fingerprinting step that frequently narrows the target's platform before deeper probing.
- ✓
Request a deliberately nonexistent path and analyze the structure of the resulting error page.
Why this is correct
Error pages differ by server and framework: Apache, Nginx, IIS, and various application frameworks each format 404 responses distinctively. Triggering a missing resource is harmless yet reveals the stack through default error templates, making it a reliable behavioral fingerprint when headers are stripped or obfuscated by a proxy.
- ✗
Run a full TCP port scan of all 65535 ports on the host to infer the web stack.
Why it's wrong here
A full port sweep identifies listening services but does not reveal which web server or framework handles HTTP. It also generates substantial traffic without answering the fingerprinting question. Port state and server technology are separate concerns, so this approach does not satisfy the goal of identifying the web stack.
- ✗
Attempt default administrative credentials against the web login form.
Why it's wrong here
Trying default credentials is an authentication attack, not fingerprinting, and it risks account lockout and alerting defenders. It also reveals nothing about the underlying server software. The task is to identify technology non-intrusively, so credential guessing falls outside scope and introduces unnecessary operational risk.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.