PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is performing initial reconnaissance on a target domain. Which THREE sources can provide historical data about the target? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Wayback Machine
The Wayback Machine archives web pages, Pastebin may contain leaked historical data, and certificate transparency logs (crt.sh) provide historical certificate issuance data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Wayback Machine
Why this is correct
The Wayback Machine, operated by the Internet Archive, captures and archives web pages at various points in time, allowing a penetration tester to retrieve old versions of a target's website. This is valuable for discovering historical content, previously exposed endpoints, old default pages, or configuration files that were later removed but may still be active or reveal security misconfigurations. Because these snapshots are timestamped, the tester can track changes over time and pinpoint when certain technologies or vulnerabilities were introduced. Unlike live tools, it provides a passive, non-intrusive source of historical data.
- ✓
Pastebin
Why this is correct
Pastebin and similar paste sites are frequently used to publicly share text snippets, including exfiltrated datasets, hardcoded credentials, or internal documentation that may contain historical information about an organization. For a penetration tester, searching Pastebin for domain-specific keywords or employee names can reveal past leaks, old passwords, or confidential information that could be leveraged during credential stuffing or phishing attacks. Because these posts are often not indexed by standard search engines, specialized OSINT queries are needed. It represents a non-intrusive source of historically leaked data, distinct from a structured archive like the Wayback Machine.
- ✗
Shodan
Why it's wrong here
Shodan is a search engine that continuously scans the Internet for open ports, banners, and services, and its results reflect the real-time or near-real-time state of devices at the time of the scan. While Shodan stores historical scan data for some devices, its primary value is identifying currently accessible devices, like exposed databases or insecure IoT systems, rather than providing reliable historical snapshots of a target's web presence. For initial reconnaissance focused on historical information, using Shodan would give a misleading picture because services may have changed or been taken offline. Moreover, Shodan queries can reveal current SSL certificates and web banners, but they do not offer the same depth of archived web content that a tool like the Wayback Machine does.
- ✓
Certificate Transparency logs (crt.sh)
Why this is correct
Certificate Transparency (CT) logs are an append-only ledger of every TLS/SSL certificate issued by participating certificate authorities, viewable through services like crt.sh. Since certificates must be logged to be trusted by browsers, these logs provide a comprehensive, immutable historical record of all domains and subdomains for which a certificate has ever been issued. A penetration tester can query these logs to enumerate current and defunct subdomains, including those that have been removed from DNS or that were used only for internal services—information that is not available in live scans. This is a powerful passive OSINT technique because it reveals the target's infrastructure history without sending any packets to the target.
- ✗
Nmap
Why it's wrong here
Nmap is a network scanning tool that actively sends probes to a target to discover open ports, running services, and operating system versions, thus providing a snapshot of the target's current state at the moment of the scan. Because it interacts directly with the target, Nmap is considered an active reconnaissance tool and its results can be affected by firewalls, load balancers, or intrusion detection systems. It does not archive historical data, so it cannot show what a target looked like in the past, making it unsuitable for initial historical reconstruction. Additionally, using Nmap without proper authorization may be considered intrusive and could trigger alerts, while historical sources are passive and less detectable.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.