SY0-701 exam dumps

SY0-701 practice question 289 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 289

Single answerEnumeration

A security analyst is validating the scope of an internal penetration test and wants to identify exposed services, shared resources, and user/account information on several Windows and Linux hosts before attempting any exploitation. The analyst must use techniques that actively gather detailed information from the targets, not passive research from public sources. Which of the following best describes this phase of the assessment?

  1. A

    Enumeration

  2. B

    Passive reconnaissance

  3. C

    Hash cracking

  4. D

    Containment

Show answer and explanation

Correct answer: A

Explanation

The correct answer is Enumeration. In practical assessments, enumeration follows initial discovery/scanning and involves actively querying discovered hosts to extract meaningful details such as user accounts, network shares, running services, SNMP information, and other accessible resources. This information helps the tester understand attack surface and identify likely paths for privilege escalation or lateral movement. By contrast, passive reconnaissance avoids direct interaction with the target. Security+ objectives commonly distinguish reconnaissance from enumeration by emphasizing that enumeration is active and target-focused. This aligns with standard security testing methodology and guidance such as NIST SP 800-115, which describes technical information gathering and active testing techniques used during security assessments.

  • A. Correct.

    Correct. Enumeration is the active process of connecting to target systems and extracting detailed information such as open services, SMB shares, SNMP data, users, groups, hostnames, and other network resources. In a Security+ context, this goes beyond simple discovery and involves interacting with targets to identify available accounts, services, and exposed resources that could support later attack steps.

  • B. Incorrect.

    Incorrect. Passive reconnaissance gathers information without directly interacting with the target systems, such as collecting data from public websites, DNS records, social media, job postings, or search engines. The scenario specifically states that the analyst is actively gathering details from the hosts themselves, which aligns with enumeration rather than passive methods.

  • C. Incorrect.

    Incorrect. Hash cracking is the process of attempting to recover plaintext passwords from password hashes, typically after credentials or dumps have already been obtained. It is not the phase focused on identifying exposed services, shares, or account information directly from live hosts.

  • D. Incorrect.

    Incorrect. Containment is an incident response activity used to limit the spread or impact of a security incident. It is not part of a penetration tester's information-gathering phase and does not describe actively querying hosts for users, services, or resources.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam