PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is performing passive reconnaissance on a target organization. Which of the following tools is best suited for gathering information from public sources such as search engines, social media, and website scraping?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
theHarvester
theHarvester is an OSINT tool designed to gather emails, subdomains, IPs, and URLs from public sources like search engines and social media.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
theHarvester
Why this is correct
theHarvester is an OSINT tool that passively collects email addresses, subdomains, hostnames, and employee names from public sources such as Google, Bing, LinkedIn, and PGP key servers. It operates without sending any packets directly to the organization's own infrastructure, so it is undetectable and strictly non-intrusive. While it can optionally perform DNS brute forcing when run in active mode, its standard use aligns with passive reconnaissance efforts during the planning phase.
- ✗
Metasploit
Why it's wrong here
Metasploit is a penetration testing framework centered on exploit development, payload delivery, and post-exploitation, not on passive information gathering. Even its auxiliary modules, such as port scanners or SMB enumeration, actively connect to target systems, generating traffic that can trigger network defenses. Using Metasploit during a passive phase would violate the fundamental assumption of no direct contact with the target and is likely to be detected.
- ✗
Nessus
Why it's wrong here
Nessus is a commercial vulnerability scanner that actively probes hosts using thousands of plugins to detect open ports, missing patches, and configuration issues. These probes are sent directly to the target network and produce observable traffic, making the scan noisy and easily caught by intrusion detection systems. As such, Nessus is an active scanning tool, never a component of passive OSINT collection.
- ✗
Nmap
Why it's wrong here
Nmap is a network reconnaissance utility that inspects targets by sending crafted packets—such as SYN scans, UDP probes, and ICMP pings—to enumerate hosts, ports, and services. Its active probing is detectable by firewalls, IDS, and host-based logging, so it is not suitable for passive reconnaissance. Unlike OSINT tools that query third-party databases, Nmap directly interacts with the target infrastructure.
Go deeper
Related to this question
Learn chapter
Phishing Campaigns in Penetration Testing
Key term
OSINT
OSINT (Open Source Intelligence) is the practice of collecting and analyzing publicly available information from free or commercially available sources to support intelligence gathering, cybersecurity assessments, and penetration testing.
Key term
Passive reconnaissance
Passive reconnaissance is the process of gathering information about a target system or network without directly interacting with it, using publicly available sources and stealthy observation.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.