mediumMultiple Select
PT0-002 Practice Question: A penetration tester is conducting an external…
A penetration tester is conducting an external assessment of a target organization and wants to gather information without sending any packets that might be logged by the target's network monitoring systems. Which TWO of the following methods are considered passive reconnaissance?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Shodan to identify exposed services
Option C is correct because Shodan is a third-party search engine that indexes internet-facing services from data it has already collected, so querying it does not send any traffic to the target's own infrastructure and therefore cannot be logged by the target's monitoring systems. Option D is correct because WHOIS lookups query public domain registration databases maintained by registrars and registries, retrieving ownership, contact, and nameserver data without touching the target's network. Option A is not passive reconnaissance but an active social-engineering attack that directly contacts employees. Option B is active because nslookup sends DNS queries directly to the target's DNS servers, generating loggable traffic. Option E is active because an Nmap port scan sends packets to the target's hosts and is readily detected by IDS/IPS and firewall logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Send spear-phishing emails to employees
Why it's wrong here
Spear-phishing sends packets to the target's mail infrastructure and solicits employee responses, making it active reconnaissance that monitoring can log. It tempts because it gathers information, but passive methods rely on public sources such as WHOIS, DNS records and OSINT without touching target systems.
- ✗
Query the target's DNS servers using nslookup
Why it's wrong here
nslookup sends queries directly to the target's DNS servers, generating log entries on those servers, so it is active reconnaissance. It is tempting because DNS lookups feel low-impact and non-intrusive, and querying DNS would suit scenarios where the tester accepts some target-side visibility.
- ✓
Use Shodan to identify exposed services
Why this is correct
Shodan serves pre-collected scan data from its own internet-wide crawling, so querying it never touches the target's hosts. No traffic reaches the organisation's network monitoring systems, satisfying the requirement to gather information without sending packets the target could log.
- ✓
Conduct WHOIS lookups on the target's domain
Why this is correct
WHOIS queries hit public registry databases maintained by registrars, not the target's infrastructure, so no packets reach its network and nothing appears in its monitoring logs. This satisfies the stem's requirement to gather information without triggering the target's logging.
- ✗
Perform a full port scan using Nmap
Why it's wrong here
Nmap's full port scan transmits packets to the target's hosts, which network monitoring systems record, making it active reconnaissance. It is tempting because port scanning is a core discovery technique, and it would be correct once the tester accepts direct interaction with the target.
Go deeper
Related to this question
Learn chapter
Python for Penetration Testing
Key term
Passive reconnaissance
Passive reconnaissance is the process of gathering information about a target system or network without directly interacting with it, using publicly available sources and stealthy observation.
Key term
Shodan
Shodan is a search engine that lets you find specific types of internet-connected devices, such as webcams, routers, and servers, by scanning the internet and indexing their services and banners.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.