Courseiva
mediumMultiple Choice

PT0-002 Practice Question: A penetration tester is conducting passive…

A penetration tester is conducting passive reconnaissance on a target organization. Which of the following techniques would provide the MOST useful information about internal network architecture without directly interacting with the target's systems?

⚠ Common exam trap

Watch out — candidates often confuse passive reconnaissance with low-interaction techniques like WHOIS lookups or zone transfers, not realizing that zone transfers and Nmap scans are active techniques that directly interact with the target's systems, while Certificate Transparency logs are a purely passive, third-party data source.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Searching for the target's SSL certificates in Certificate Transparency logs

Certificate Transparency (CT) logs are publicly accessible, append-only ledgers of SSL/TLS certificates. By searching CT logs for certificates issued to the target organization, a penetration tester can discover subdomains, hostnames, and even internal-facing server names that are included in Subject Alternative Names (SANs) or Common Names (CNs). This reveals internal network architecture details (e.g., 'mail.internal.example.com') without any direct interaction with the target's systems, making it a purely passive reconnaissance technique.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Performing a zone transfer against the target's DNS servers

    Why it's wrong here

    A zone transfer (AXFR query) is an active DNS operation that connects directly to the target's nameservers, so it generates query logs and is often restricted to authorized IPs. Sending this query is a direct interaction with target infrastructure, not passive observation, and many modern DNS servers reject AXFR entirely. Even if successful, you'd be relying on the target's own DNS records rather than independent public data, so it fails the requirement of passive reconnaissance.

  • ✓

    Searching for the target's SSL certificates in Certificate Transparency logs

    Why this is correct

    Certificate Transparency (CT) logs are public, append-only ledgers of TLS certificates maintained by Google, Cloudflare, and other CAs; you can query them via services like crt.sh without ever contacting the target's servers. Every publicly trusted certificate issued for a domain is logged, including those for subdomains that aren't listed in DNS or linked anywhere, making this a passive way to enumerate the target's attack surface. Because CT logs are independently audited and immutable, they also provide historical certificate data that may reveal decommissioned or internal hostnames.

  • ✗

    Using Nmap to scan common ports on the target's public IP range

    Why it's wrong here

    An Nmap port scan sends crafted network probes (SYN packets, TCP connects, etc.) to the target's public IP range, which is active scanning and immediately generates traffic on the target's network perimeter, often triggering IDS/IPS alerts or firewall logs. Passive reconnaissance never involves sending packets to the target; it relies on information already available from third-party sources. Therefore, even a 'light' Nmap scan is out of scope for passive recon and could violate the engagement's authorization or the target's protections.

  • ✗

    Querying the target's WHOIS records for IP addresses

    Why it's wrong here

    WHOIS queries are passive because they access public registration data, but they only reveal administrative contacts, registrar information, and nameservers—not internal IP addressing, hostnames, or subdomain structure. WHOIS for IP address blocks (e.g., ARIN, RIPE) shows the organization's registered network range and abuse contact, but it doesn't enumerate hosts within that range. Thus, while WHOIS is a valid passive OSINT source, it doesn't help discover hidden internal subdomains, which is the goal this technique is intended to achieve.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.