Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is conducting passive reconnaissance and wants to gather information about a target organization's employees, email addresses, and internal structure. Which TWO tools are best suited for this purpose? (Select TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Maltego

Maltego is a data mining tool that visualizes relationships and can collect info from social media, DNS, and other sources. theHarvester gathers emails, subdomains, and names from public sources. LinkedIn is also used for organizational chart mapping, but the question asks for tools specifically.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Maltego

    Why this is correct

    Maltego is a passive OSINT and data-mining tool that aggregates information from public sources such as social media, DNS records, and certificate transparency logs. It uses transforms to pivot between entities — for example, from a domain to an employee email, then to a linked social profile — revealing organizational relationships without ever touching the target's infrastructure. This relationship graphing makes it ideal for passively mapping an organization's attack surface and employee information.

  • ✗

    Gobuster

    Why it's wrong here

    Gobuster is an active brute-force tool used primarily to discover hidden web directories and files by sending a high volume of HTTP requests to the target web server. While it can also enumerate DNS subdomains, every request goes directly to the target's infrastructure, generating network traffic that can be logged or detected by a WAF or IDS. Because it actively interacts with the target and does not consult third-party OSINT sources, it is unsuitable for passive reconnaissance or gathering employee/email details.

  • ✗

    Nmap

    Why it's wrong here

    Nmap is a powerful network scanning tool that actively sends crafted packets to target hosts to identify open ports, running services, and OS fingerprints. These probes generate detectable traffic on the target network and can trigger intrusion detection systems, making them a hallmark of active reconnaissance. Since passive recon requires no direct interaction with the target's systems, Nmap's active scanning methodology invalidates it for the stated task.

  • ✓

    theHarvester

    Why this is correct

    theHarvester is a dedicated passive OSINT recon tool that queries publicly accessible data sources — including Google, Bing, PGP key servers, and the Shodan API — to harvest email addresses, employee names, subdomains, and virtual hosts. It never transmits packets to the target's own servers; it only receives public data from third-party providers. This makes it a precise fit for passive employee and email enumeration, though it lacks Maltego's advanced relationship charting.

  • ✗

    Nikto

    Why it's wrong here

    Nikto is an active web vulnerability scanner that sends thousands of HTTP requests to a target web server to detect outdated software, dangerous files, and misconfigurations. Its aggressive scanning generates significant server-side log entries and may crash fragile applications, clearly crossing over from passive to active reconnaissance. Moreover, its primary focus is web server vulnerability detection, not extracting employee names or email addresses from OSINT sources, so it fails the task entirely.

Go deeper

Related to this question

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.