PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is performing DNS reconnaissance and wants to enumerate all subdomains of a target domain by querying DNS servers in an attempt to transfer the entire zone file. Which technique is the tester using?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS zone transfer
DNS zone transfer (AXFR) is a mechanism that allows a secondary DNS server to replicate the entire zone file from a primary server. If misconfigured, anyone can request it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DNS zone transfer
Why this is correct
A DNS zone transfer (AXFR) is a legitimate replication mechanism that copies the entire zone file from a primary to a secondary DNS server. When misconfigured to allow unrestricted AXFR, it exposes every record in the zone, including internal host names, IP addresses, and service records, giving an attacker a complete map of the target's network. This makes it the definitive enumeration technique because it returns the full data set in one query.
- ✗
DNS reverse lookup
Why it's wrong here
DNS reverse lookup queries the PTR record to map a specific IP address back to a hostname, functioning as a one-to-one resolution rather than a bulk data retrieval. To enumerate subdomains this way, a tester would need to already know an entire IP range and perform a reverse DNS scan, which only reveals names for active addresses and is both slow and incomplete. It does not request the zone file, so it cannot expose the full list of hostnames that a zone transfer would reveal.
- ✗
DNS cache snooping
Why it's wrong here
DNS cache snooping involves sending a query to a recursive resolver for a specific domain name and determining whether that record is already in its cache, often by measuring response time or the presence of the 'Non-Authoritative' flag. This reveals what other clients have recently queried, potentially exposing user activity or internal hostnames, but it only provides a yes/no answer for the single queried name. It cannot dump the entire zone and is therefore not a subdomain enumeration technique like a zone transfer.
- ✗
DNS tunneling
Why it's wrong here
DNS tunneling is a covert communication method that encapsulates non-DNS payloads, such as HTTP or SSH, within DNS query and response packets, typically using subdomain labels or TXT records for data exfiltration and command-and-control. The attacker operates their own authoritative server to receive the tunneled data, which has nothing to do with the victim's zone contents. It is an evasion and C2 technique, not a reconnaissance method, and thus cannot reveal the target's complete DNS records like a zone transfer.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.