PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is performing passive reconnaissance on a target organization. Which of the following tools would be BEST suited to gather information about the organization's domain names, email addresses, and subdomains from publicly available sources without directly interacting with the target's systems?
⚠ Common exam trap
PT0-003 often tests the confusion between passive and active reconnaissance tools, where candidates might pick Nmap or Nessus thinking they are passive when they actually generate network traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
theHarvester
theHarvester is specifically designed for passive reconnaissance, gathering domain names, email addresses, subdomains, and other publicly available information from search engines and public sources without directly interacting with the target's systems. It queries sources like Google, Bing, and LinkedIn, making it ideal for this task.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Nmap
Why it's wrong here
Nmap sends probes directly to target hosts, which is active reconnaissance and would reveal the tester's presence. It is tempting because it excels at port and service discovery once authorised scanning begins, but the scenario forbids touching the target's systems at all.
- ✓
theHarvester
Why this is correct
theHarvester queries public sources such as search engines, PGP key servers and certificate transparency logs to harvest domain names, email addresses and subdomains. This satisfies the passive constraint because it never sends traffic directly to the target's own systems.
- ✗
Nessus
Why it's wrong here
Nessus authenticates to and scans live hosts for vulnerabilities, generating traffic the target can log, so it violates the passive-only requirement. It is tempting as the standard vulnerability scanner during later assessment phases, yet it cannot collect domain, email or subdomain data from public sources.
- ✗
Metasploit
Why it's wrong here
Metasploit is an exploitation framework for launching payloads against live hosts, so it requires direct interaction and cannot harvest OSINT from public sources. It tempts testers during active exploitation once a vulnerability is confirmed, but passive reconnaissance demands querying third-party databases and search engines instead.
Go deeper
Related to this question
Learn chapter
Penetration Testing Tools
Key term
theHarvester
theHarvester is an open-source intelligence (OSINT) tool used to gather emails, subdomains, IP addresses, and other public data about a target from search engines and public sources.
Key term
Passive reconnaissance
Passive reconnaissance is the process of gathering information about a target system or network without directly interacting with it, using publicly available sources and stealthy observation.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.