easyMultiple Choice
PT0-002 Practice Question: A penetration tester is conducting passive…
A penetration tester is conducting passive reconnaissance on a target organization. Which technique can be used to discover subdomains of the target's domain without sending any packets to the target's network?
⚠ Common exam trap
Test-takers frequently confuse passive reconnaissance with techniques that appear passive but still send packets (like DNS brute-force or ICMP echo requests), or they incorrectly assume WHOIS queries can enumerate subdomains when WHOIS only provides registration metadata.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using the 'site:' operator in a search engine query
Using the 'site:' operator in a search engine query (e.g., 'site:example.com') retrieves indexed subdomains from the search engine's cache without sending any packets to the target's network. This is a purely passive technique that leverages publicly available data, aligning with the definition of passive reconnaissance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Performing a DNS brute-force attack against the target's domain
Why it's wrong here
Performing a DNS brute-force attack is active reconnaissance because it sends thousands of crafted DNS queries directly to the target's authoritative nameservers. These queries are logged, and the volume of requests can trigger rate limiting, security analytics, or alerting on the DNS infrastructure. This direct interaction with the target's systems makes it detectable and disqualifies it as passive reconnaissance.
- ✓
Using the 'site:' operator in a search engine query
Why this is correct
Using the 'site:' search engine operator is a purely passive technique because you are querying a third-party search index rather than touching the target's infrastructure. Search engines crawl and recursively list indexed subdomains under 'example.com', revealing them without generating any traffic to the target. This makes it an ideal OSINT method for subdomain discovery.
- ✗
Sending ICMP echo requests to potential subdomain IP addresses
Why it's wrong here
Sending ICMP echo requests, or pings, to candidate subdomain IP addresses constitutes active reconnaissance because the target's hosts receive and respond to your packets. Intrusion detection systems, network firewalls, and host logs can easily capture this traffic, and unexpected ICMP probes may raise alarms. Since passive reconnaissance must avoid any direct contact, this option is ruled out.
- ✗
Querying WHOIS databases for domain registration information
Why it's wrong here
Querying WHOIS databases is passive since it only accesses registry records, but these records contain registration details such as registrant, nameservers, and expiration dates—not a listing of subdomains. WHOIS results do not reveal hostname-level information that would identify 'sub.example.com' or similar records. It is therefore the wrong tool for subdomain enumeration.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.