PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is performing passive reconnaissance on a target organization. Which of the following tools would be BEST for discovering subdomains and email addresses associated with the target domain without sending any packets to the target?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
theHarvester
theHarvester is an OSINT tool that collects emails, subdomains, IPs, and URLs from public sources like search engines and PGP key servers without interacting with the target network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WPScan
Why it's wrong here
WPScan is an active WordPress vulnerability scanner that sends crafted HTTP requests to the target site to enumerate installed plugins, themes, and users, and to probe for known vulnerabilities. These interactions produce server logs and network traffic that the target can detect, so it violates the requirement for passive reconnaissance. Even in its most basic mode, it must connect to the target's web server, unlike tools that simply observe publicly available data without touching the target.
- ✗
Nmap
Why it's wrong here
Nmap actively probes target hosts by sending crafted IP packets (e.g., TCP SYN scans, ICMP echo requests, UDP datagrams) and analyzing the responses to discover open ports, services, and operating system fingerprints. This direct interaction with live infrastructure is the archetype of active reconnaissance, as it generates detectable network traffic and can trigger intrusion detection or firewall alerts. Passive reconnaissance, by contrast, never sends packets to the target system itself.
- ✗
snmpwalk
Why it's wrong here
snmpwalk is an active enumeration tool that sends repeated GETNEXT requests to an SNMP-enabled device's UDP port 161 to walk its Management Information Base (MIB) tree and extract system details like interfaces, running processes, and user accounts. To receive this data, the tool must communicate with the target in real time, making it an active query that can be logged and detected. It also requires valid community strings, which often comes from prior active brute-force or sniffing activity, further disqualifying it as passive.
- ✓
theHarvester
Why this is correct
theHarvester is a passive OSINT tool that aggregates publicly accessible information from third-party sources such as search engines, PGP key servers, and certificate transparency logs to collect email addresses, subdomains, hosts, and employee names for a given domain. It never sends packets directly to the target's own infrastructure, so it does not trigger target-side monitoring or violate the passive reconnaissance constraint. Its value lies in building a pre-attack picture of the attack surface from information already available on the internet, making it ideal for the passive phase.
Go deeper
Related to this question
Learn chapter
Penetration Testing Methodology
Key term
theHarvester
theHarvester is an open-source intelligence (OSINT) tool used to gather emails, subdomains, IP addresses, and other public data about a target from search engines and public sources.
Key term
OSINT
OSINT (Open Source Intelligence) is the practice of collecting and analyzing publicly available information from free or commercially available sources to support intelligence gathering, cybersecurity assessments, and penetration testing.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.