Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is performing passive reconnaissance on a target organization. Which of the following tools would be BEST suited to gather information about the organization's domain names, email addresses, and subdomains from publicly available sources without directly interacting with the target's systems?

⚠ Common exam trap

PT0-003 often tests the confusion between passive and active reconnaissance tools, where candidates might pick Nmap or Nessus thinking they are passive when they actually generate network traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

theHarvester

theHarvester is specifically designed for passive reconnaissance, gathering domain names, email addresses, subdomains, and other publicly available information from search engines and public sources without directly interacting with the target's systems. It queries sources like Google, Bing, and LinkedIn, making it ideal for this task.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Nmap

    Why it's wrong here

    Nmap sends probes directly to target hosts, which is active reconnaissance and would reveal the tester's presence. It is tempting because it excels at port and service discovery once authorised scanning begins, but the scenario forbids touching the target's systems at all.

  • ✓

    theHarvester

    Why this is correct

    theHarvester queries public sources such as search engines, PGP key servers and certificate transparency logs to harvest domain names, email addresses and subdomains. This satisfies the passive constraint because it never sends traffic directly to the target's own systems.

  • ✗

    Nessus

    Why it's wrong here

    Nessus authenticates to and scans live hosts for vulnerabilities, generating traffic the target can log, so it violates the passive-only requirement. It is tempting as the standard vulnerability scanner during later assessment phases, yet it cannot collect domain, email or subdomain data from public sources.

  • ✗

    Metasploit

    Why it's wrong here

    Metasploit is an exploitation framework for launching payloads against live hosts, so it requires direct interaction and cannot harvest OSINT from public sources. It tempts testers during active exploitation once a vulnerability is confirmed, but passive reconnaissance demands querying third-party databases and search engines instead.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.