TechNuggets Academy

Reconnaissance and Enumeration

Free CompTIA PenTest+ practice — 6 questions on Reconnaissance and Enumeration, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Reconnaissance and Enumeration
A pentester is in the passive information-gathering phase of an authorized external engagement and must avoid any direct interaction with the target organization's DNS infrastructure. The tester wants to discover subdomains that may not appear in normal DNS records. Which technique BEST satisfies these constraints?
Certificate transparency logs are public records maintained by third-party CT log servers, so querying crt.sh reveals subdomains from issued TLS certificates without ever touching the target's own DNS servers or network, making it a truly passive technique.
Question 2 of 6 · Reconnaissance and Enumeration
During an authorized internal assessment, a tester has no valid domain credentials but discovers that null sessions are permitted on a Windows file server. The tester needs to enumerate shares, local user accounts, and the configured password policy through this null session. Which tool BEST accomplishes this?
enum4linux is purpose-built to enumerate Windows/Samba systems over SMB using null or guest sessions, extracting share lists, user accounts, group membership, and password policy information.
Question 3 of 6 · Reconnaissance and Enumeration
A tester finds the following PowerShell one-liner in a recon script repository used during an internal Active Directory assessment: `Get-ADUser -Filter * -Properties PasswordNeverExpires | Where-Object {$_.PasswordNeverExpires -eq $true}`. What is this script enumerating?
Get-ADUser retrieves domain user objects, and filtering on the PasswordNeverExpires property being true returns the list of AD user accounts whose password expiration is disabled, a high-value target list for credential attacks.
Question 4 of 6 · Reconnaissance and Enumeration
A pentester needs to identify potentially misconfigured, publicly accessible cloud storage buckets tied to a target's brand names during the passive OSINT phase of an authorized engagement. No cloud credentials have been provided in scope. Which approach is MOST appropriate?
Bucket search engines and naming-convention permutation against known bucket-naming patterns allow a tester to discover exposed buckets using only public DNS/HTTP requests to AWS-owned endpoints, staying within a passive/low-impact OSINT approach and not requiring or misusing any credentials.
Question 5 of 6 · Reconnaissance and Enumeration
While enumerating hosts on a scoped internal network segment, a tester finds UDP 161 open on a network printer. Which technique is MOST appropriate to enumerate the device's system description and configured community strings?
UDP 161 indicates SNMP, and many devices, especially printers, ship with default read-only community strings such as "public." Running snmpwalk with this string is the standard enumeration technique to pull system information, interface details, and configuration data via SNMP.
Question 6 of 6 · Reconnaissance and Enumeration
A wireless assessment's rules of engagement explicitly prohibit transmitting any frames that could disrupt legitimate wireless clients. The tester still needs to identify nearby SSIDs, BSSIDs, and encryption types in scope. Which approach satisfies this constraint?
Placing a wireless adapter in monitor mode and passively capturing beacon and probe frames with Kismet or airodump-ring allows identification of SSIDs, BSSIDs, and encryption types without transmitting any frames, fully complying with a no-disruption constraint.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →