Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is performing passive reconnaissance on a target organization. Which of the following tools is best suited for gathering information from public sources such as search engines, social media, and website scraping?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

theHarvester

theHarvester is an OSINT tool designed to gather emails, subdomains, IPs, and URLs from public sources like search engines and social media.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    theHarvester

    Why this is correct

    theHarvester is an OSINT tool that passively collects email addresses, subdomains, hostnames, and employee names from public sources such as Google, Bing, LinkedIn, and PGP key servers. It operates without sending any packets directly to the organization's own infrastructure, so it is undetectable and strictly non-intrusive. While it can optionally perform DNS brute forcing when run in active mode, its standard use aligns with passive reconnaissance efforts during the planning phase.

  • ✗

    Metasploit

    Why it's wrong here

    Metasploit is a penetration testing framework centered on exploit development, payload delivery, and post-exploitation, not on passive information gathering. Even its auxiliary modules, such as port scanners or SMB enumeration, actively connect to target systems, generating traffic that can trigger network defenses. Using Metasploit during a passive phase would violate the fundamental assumption of no direct contact with the target and is likely to be detected.

  • ✗

    Nessus

    Why it's wrong here

    Nessus is a commercial vulnerability scanner that actively probes hosts using thousands of plugins to detect open ports, missing patches, and configuration issues. These probes are sent directly to the target network and produce observable traffic, making the scan noisy and easily caught by intrusion detection systems. As such, Nessus is an active scanning tool, never a component of passive OSINT collection.

  • ✗

    Nmap

    Why it's wrong here

    Nmap is a network reconnaissance utility that inspects targets by sending crafted packets—such as SYN scans, UDP probes, and ICMP pings—to enumerate hosts, ports, and services. Its active probing is detectable by firewalls, IDS, and host-based logging, so it is not suitable for passive reconnaissance. Unlike OSINT tools that query third-party databases, Nmap directly interacts with the target infrastructure.

Go deeper

Related to this question

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.