Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is performing passive reconnaissance on a target organization. Which of the following tools would be BEST for discovering subdomains and email addresses associated with the target domain without sending any packets to the target?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

theHarvester

theHarvester is an OSINT tool that collects emails, subdomains, IPs, and URLs from public sources like search engines and PGP key servers without interacting with the target network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    WPScan

    Why it's wrong here

    WPScan is an active WordPress vulnerability scanner that sends crafted HTTP requests to the target site to enumerate installed plugins, themes, and users, and to probe for known vulnerabilities. These interactions produce server logs and network traffic that the target can detect, so it violates the requirement for passive reconnaissance. Even in its most basic mode, it must connect to the target's web server, unlike tools that simply observe publicly available data without touching the target.

  • ✗

    Nmap

    Why it's wrong here

    Nmap actively probes target hosts by sending crafted IP packets (e.g., TCP SYN scans, ICMP echo requests, UDP datagrams) and analyzing the responses to discover open ports, services, and operating system fingerprints. This direct interaction with live infrastructure is the archetype of active reconnaissance, as it generates detectable network traffic and can trigger intrusion detection or firewall alerts. Passive reconnaissance, by contrast, never sends packets to the target system itself.

  • ✗

    snmpwalk

    Why it's wrong here

    snmpwalk is an active enumeration tool that sends repeated GETNEXT requests to an SNMP-enabled device's UDP port 161 to walk its Management Information Base (MIB) tree and extract system details like interfaces, running processes, and user accounts. To receive this data, the tool must communicate with the target in real time, making it an active query that can be logged and detected. It also requires valid community strings, which often comes from prior active brute-force or sniffing activity, further disqualifying it as passive.

  • ✓

    theHarvester

    Why this is correct

    theHarvester is a passive OSINT tool that aggregates publicly accessible information from third-party sources such as search engines, PGP key servers, and certificate transparency logs to collect email addresses, subdomains, hosts, and employee names for a given domain. It never sends packets directly to the target's own infrastructure, so it does not trigger target-side monitoring or violate the passive reconnaissance constraint. Its value lies in building a pre-attack picture of the attack surface from information already available on the internet, making it ideal for the passive phase.

Go deeper

Related to this question

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.