Courseiva
mediumMultiple Select

PT0-002 Practice Question: A penetration tester is conducting an external…

A penetration tester is conducting an external assessment of a target organization and wants to gather information without sending any packets that might be logged by the target's network monitoring systems. Which TWO of the following methods are considered passive reconnaissance?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Shodan to identify exposed services

Option C is correct because Shodan is a third-party search engine that indexes internet-facing services from data it has already collected, so querying it does not send any traffic to the target's own infrastructure and therefore cannot be logged by the target's monitoring systems. Option D is correct because WHOIS lookups query public domain registration databases maintained by registrars and registries, retrieving ownership, contact, and nameserver data without touching the target's network. Option A is not passive reconnaissance but an active social-engineering attack that directly contacts employees. Option B is active because nslookup sends DNS queries directly to the target's DNS servers, generating loggable traffic. Option E is active because an Nmap port scan sends packets to the target's hosts and is readily detected by IDS/IPS and firewall logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Send spear-phishing emails to employees

    Why it's wrong here

    Spear-phishing sends packets to the target's mail infrastructure and solicits employee responses, making it active reconnaissance that monitoring can log. It tempts because it gathers information, but passive methods rely on public sources such as WHOIS, DNS records and OSINT without touching target systems.

  • ✗

    Query the target's DNS servers using nslookup

    Why it's wrong here

    nslookup sends queries directly to the target's DNS servers, generating log entries on those servers, so it is active reconnaissance. It is tempting because DNS lookups feel low-impact and non-intrusive, and querying DNS would suit scenarios where the tester accepts some target-side visibility.

  • ✓

    Use Shodan to identify exposed services

    Why this is correct

    Shodan serves pre-collected scan data from its own internet-wide crawling, so querying it never touches the target's hosts. No traffic reaches the organisation's network monitoring systems, satisfying the requirement to gather information without sending packets the target could log.

  • ✓

    Conduct WHOIS lookups on the target's domain

    Why this is correct

    WHOIS queries hit public registry databases maintained by registrars, not the target's infrastructure, so no packets reach its network and nothing appears in its monitoring logs. This satisfies the stem's requirement to gather information without triggering the target's logging.

  • ✗

    Perform a full port scan using Nmap

    Why it's wrong here

    Nmap's full port scan transmits packets to the target's hosts, which network monitoring systems record, making it active reconnaissance. It is tempting because port scanning is a core discovery technique, and it would be correct once the tester accepts direct interaction with the target.

Go deeper

Related to this question

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.