mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is performing reconnaissance…
A penetration tester is performing reconnaissance on a target organization and uses Shodan to find internet-facing devices. Which of the following is the BEST use case for Shodan in this context?
⚠ Common exam trap
Candidates often confuse Shodan's banner-gathering capability with active DNS enumeration or web scraping, leading them to select options that describe unrelated reconnaissance tasks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Discovering open ports and services on public IP ranges
Shodan is a search engine for internet-connected devices that scans public IP ranges and indexes the banners returned by services. Its primary use in reconnaissance is to discover open ports and running services on target IP ranges, revealing attack surface such as exposed databases, web servers, or industrial control systems. This aligns directly with the information-gathering phase of a penetration test.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Identifying subdomains through DNS brute-forcing
Why it's wrong here
Shodan is an internet-connected device search engine that indexes banners from network services, not a DNS enumeration tool. Subdomain identification through DNS brute-forcing relies on sending many DNS lookup queries (e.g., against a wordlist) to see which hostnames resolve, using tools like dnsrecon, sublist3r, or amass. While Shodan's reverse DNS and SSL certificate data might reveal a few hostnames incidentally, its functionality does not include performing DNS brute-force attacks, making it the wrong tool for this specific reconnaissance task.
- ✓
Discovering open ports and services on public IP ranges
Why this is correct
Shodan continuously scans the public IPv4 address space (and some IPv6) and stores the service banners it collects from open ports. A penetration tester can query Shodan for a target organization's public IP ranges using the `net:` filter to instantly discover exposed ports, identify running services and their versions, and detect misconfigurations or unpatched software. This provides a passive, external view of the attack surface before any active scanning is performed, which is both efficient and useful for planning further intrusion attempts.
- ✗
Enumerating email addresses from corporate websites
Why it's wrong here
Shodan does not crawl websites or parse contact pages to harvest email addresses; its primary dataset consists of network-level banner information from open ports. Enumerating corporate email addresses is typically accomplished by using OSINT tools like theHarvester, scraping the target's website, or querying search engines. Although a Shodan banner might occasionally contain an email address (e.g., in a mail server greeting), this is an inconsistent afterthought rather than a deliberate capability, so Shodan is not suitable for systematic email enumeration.
- ✗
Extracting metadata from documents found on the target's website
Why it's wrong here
Metadata extraction involves downloading files (such as PDFs or Office documents) from the target's website and then parsing their internal metadata (e.g., author names, GPS coordinates, software versions) with offline tools like FOCA, ExifTool, or exiftool. Shodan neither retrieves documents from websites nor parses file structures; it only stores banner data from its port scanning. Consequently, this reconnaissance activity falls entirely outside Shodan's feature set and would be performed using dedicated metadata analysis tools after manually harvesting the files.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.