Courseiva
easyMultiple Choice

PT0-002 Practice Question: A penetration tester is performing passive…

A penetration tester is performing passive reconnaissance on a target organization. Which of the following activities would be considered passive reconnaissance?

⚠ Common exam trap

It's easy for candidates to confuse 'passive' with 'low-interaction' activities, mistakenly thinking that sending a single ICMP packet or a simple port scan is passive because it seems minimal, but any direct packet transmission to the target constitutes active reconnaissance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using a search engine to find exposed documents

Passive reconnaissance involves gathering information without directly interacting with the target's systems. Using a search engine to find exposed documents (e.g., via Google dorking) relies on publicly indexed data, which does not send any packets to the target's infrastructure. This aligns with the definition of passive reconnaissance as it leverages third-party sources rather than engaging the target directly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Scanning open ports on the target web server

    Why it's wrong here

    Port scanning the target web server requires sending TCP connection requests, such as SYN or full three-way handshake packets, to enumerate open services; this traffic is directed at the target and can be detected. Because the scanner is actively probing the system and generating measurable network activity, it is unequivocally an active reconnaissance technique.

  • ✓

    Using a search engine to find exposed documents

    Why this is correct

    Querying a search engine like Google or Shodan returns information from the search provider's indexed cache rather than contacting the target's own systems. This means no packets are sent to the target itself, so retrieving exposed documents, metadata, or cached pages qualifies as passive reconnaissance and leaves no trace in the target's logs.

  • ✗

    Sending a crafted ICMP echo request to the target

    Why it's wrong here

    Crafting an ICMP echo request involves directly transmitting a ping packet to the target's IP address and awaiting an ICMP echo reply, which is a live interaction with the host. This active probe reveals the target's reachability and OS quirks, but because it sends a packet that the target's network monitoring can observe, it is classified as active reconnaissance.

  • ✗

    Attempting a SQL injection on a login form

    Why it's wrong here

    Submitting SQL injection payloads through a login form sends malicious SQL strings into the target application to manipulate database queries, which is an exploitation attempt rather than any form of reconnaissance. This activity directly interacts with the application backend and may alter data, so it is an active attack and completely out of place in passive reconnaissance.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.