easyMultiple Choice
PT0-002 Practice Question: A penetration tester is performing passive…
A penetration tester is performing passive reconnaissance on a target organization. Which of the following activities would be considered passive reconnaissance?
⚠ Common exam trap
It's easy for candidates to confuse 'passive' with 'low-interaction' activities, mistakenly thinking that sending a single ICMP packet or a simple port scan is passive because it seems minimal, but any direct packet transmission to the target constitutes active reconnaissance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using a search engine to find exposed documents
Passive reconnaissance involves gathering information without directly interacting with the target's systems. Using a search engine to find exposed documents (e.g., via Google dorking) relies on publicly indexed data, which does not send any packets to the target's infrastructure. This aligns with the definition of passive reconnaissance as it leverages third-party sources rather than engaging the target directly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Scanning open ports on the target web server
Why it's wrong here
Port scanning the target web server requires sending TCP connection requests, such as SYN or full three-way handshake packets, to enumerate open services; this traffic is directed at the target and can be detected. Because the scanner is actively probing the system and generating measurable network activity, it is unequivocally an active reconnaissance technique.
- ✓
Using a search engine to find exposed documents
Why this is correct
Querying a search engine like Google or Shodan returns information from the search provider's indexed cache rather than contacting the target's own systems. This means no packets are sent to the target itself, so retrieving exposed documents, metadata, or cached pages qualifies as passive reconnaissance and leaves no trace in the target's logs.
- ✗
Sending a crafted ICMP echo request to the target
Why it's wrong here
Crafting an ICMP echo request involves directly transmitting a ping packet to the target's IP address and awaiting an ICMP echo reply, which is a live interaction with the host. This active probe reveals the target's reachability and OS quirks, but because it sends a packet that the target's network monitoring can observe, it is classified as active reconnaissance.
- ✗
Attempting a SQL injection on a login form
Why it's wrong here
Submitting SQL injection payloads through a login form sends malicious SQL strings into the target application to manipulate database queries, which is an exploitation attempt rather than any form of reconnaissance. This activity directly interacts with the application backend and may alter data, so it is an active attack and completely out of place in passive reconnaissance.
Go deeper
Related to this question
Learn chapter
Pentesting AI and ML Systems
Key term
Google dorking
Google dorking is the practice of using advanced search operators in Google to uncover sensitive information that companies or individuals unintentionally expose on the internet.
Key term
Passive reconnaissance
Passive reconnaissance is the process of gathering information about a target system or network without directly interacting with it, using publicly available sources and stealthy observation.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.