Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is performing initial reconnaissance on a target domain. Which THREE sources can provide historical data about the target? (Select THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Wayback Machine

The Wayback Machine archives web pages, Pastebin may contain leaked historical data, and certificate transparency logs (crt.sh) provide historical certificate issuance data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Wayback Machine

    Why this is correct

    The Wayback Machine, operated by the Internet Archive, captures and archives web pages at various points in time, allowing a penetration tester to retrieve old versions of a target's website. This is valuable for discovering historical content, previously exposed endpoints, old default pages, or configuration files that were later removed but may still be active or reveal security misconfigurations. Because these snapshots are timestamped, the tester can track changes over time and pinpoint when certain technologies or vulnerabilities were introduced. Unlike live tools, it provides a passive, non-intrusive source of historical data.

  • ✓

    Pastebin

    Why this is correct

    Pastebin and similar paste sites are frequently used to publicly share text snippets, including exfiltrated datasets, hardcoded credentials, or internal documentation that may contain historical information about an organization. For a penetration tester, searching Pastebin for domain-specific keywords or employee names can reveal past leaks, old passwords, or confidential information that could be leveraged during credential stuffing or phishing attacks. Because these posts are often not indexed by standard search engines, specialized OSINT queries are needed. It represents a non-intrusive source of historically leaked data, distinct from a structured archive like the Wayback Machine.

  • ✗

    Shodan

    Why it's wrong here

    Shodan is a search engine that continuously scans the Internet for open ports, banners, and services, and its results reflect the real-time or near-real-time state of devices at the time of the scan. While Shodan stores historical scan data for some devices, its primary value is identifying currently accessible devices, like exposed databases or insecure IoT systems, rather than providing reliable historical snapshots of a target's web presence. For initial reconnaissance focused on historical information, using Shodan would give a misleading picture because services may have changed or been taken offline. Moreover, Shodan queries can reveal current SSL certificates and web banners, but they do not offer the same depth of archived web content that a tool like the Wayback Machine does.

  • ✓

    Certificate Transparency logs (crt.sh)

    Why this is correct

    Certificate Transparency (CT) logs are an append-only ledger of every TLS/SSL certificate issued by participating certificate authorities, viewable through services like crt.sh. Since certificates must be logged to be trusted by browsers, these logs provide a comprehensive, immutable historical record of all domains and subdomains for which a certificate has ever been issued. A penetration tester can query these logs to enumerate current and defunct subdomains, including those that have been removed from DNS or that were used only for internal services—information that is not available in live scans. This is a powerful passive OSINT technique because it reveals the target's infrastructure history without sending any packets to the target.

  • ✗

    Nmap

    Why it's wrong here

    Nmap is a network scanning tool that actively sends probes to a target to discover open ports, running services, and operating system versions, thus providing a snapshot of the target's current state at the moment of the scan. Because it interacts directly with the target, Nmap is considered an active reconnaissance tool and its results can be affected by firewalls, load balancers, or intrusion detection systems. It does not archive historical data, so it cannot show what a target looked like in the past, making it unsuitable for initial historical reconstruction. Additionally, using Nmap without proper authorization may be considered intrusive and could trigger alerts, while historical sources are passive and less detectable.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.