PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is conducting passive reconnaissance and wants to gather information about a target organization's employees, email addresses, and internal structure. Which TWO tools are best suited for this purpose? (Select TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Maltego
Maltego is a data mining tool that visualizes relationships and can collect info from social media, DNS, and other sources. theHarvester gathers emails, subdomains, and names from public sources. LinkedIn is also used for organizational chart mapping, but the question asks for tools specifically.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Maltego
Why this is correct
Maltego is a passive OSINT and data-mining tool that aggregates information from public sources such as social media, DNS records, and certificate transparency logs. It uses transforms to pivot between entities — for example, from a domain to an employee email, then to a linked social profile — revealing organizational relationships without ever touching the target's infrastructure. This relationship graphing makes it ideal for passively mapping an organization's attack surface and employee information.
- ✗
Gobuster
Why it's wrong here
Gobuster is an active brute-force tool used primarily to discover hidden web directories and files by sending a high volume of HTTP requests to the target web server. While it can also enumerate DNS subdomains, every request goes directly to the target's infrastructure, generating network traffic that can be logged or detected by a WAF or IDS. Because it actively interacts with the target and does not consult third-party OSINT sources, it is unsuitable for passive reconnaissance or gathering employee/email details.
- ✗
Nmap
Why it's wrong here
Nmap is a powerful network scanning tool that actively sends crafted packets to target hosts to identify open ports, running services, and OS fingerprints. These probes generate detectable traffic on the target network and can trigger intrusion detection systems, making them a hallmark of active reconnaissance. Since passive recon requires no direct interaction with the target's systems, Nmap's active scanning methodology invalidates it for the stated task.
- ✓
theHarvester
Why this is correct
theHarvester is a dedicated passive OSINT recon tool that queries publicly accessible data sources — including Google, Bing, PGP key servers, and the Shodan API — to harvest email addresses, employee names, subdomains, and virtual hosts. It never transmits packets to the target's own servers; it only receives public data from third-party providers. This makes it a precise fit for passive employee and email enumeration, though it lacks Maltego's advanced relationship charting.
- ✗
Nikto
Why it's wrong here
Nikto is an active web vulnerability scanner that sends thousands of HTTP requests to a target web server to detect outdated software, dangerous files, and misconfigurations. Its aggressive scanning generates significant server-side log entries and may crash fragile applications, clearly crossing over from passive to active reconnaissance. Moreover, its primary focus is web server vulnerability detection, not extracting employee names or email addresses from OSINT sources, so it fails the task entirely.
Go deeper
Related to this question
Learn chapter
Penetration Testing Tools
Key term
Passive reconnaissance
Passive reconnaissance is the process of gathering information about a target system or network without directly interacting with it, using publicly available sources and stealthy observation.
Key term
Maltego
Maltego is a graphical open-source intelligence tool used for information gathering and reconnaissance, enabling users to map and visualize relationships between entities like people, domains, and networks.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.