Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is reviewing SSL/TLS certificate information for a target domain and wants to discover additional subdomains that share the same certificate. Which resource is best for this purpose?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

crt.sh

Certificate Transparency logs (e.g., crt.sh) allow searching by domain or certificate fingerprint to find all certificates issued for that domain, often revealing subdomains.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    crt.sh

    Why this is correct

    crt.sh is a certificate transparency (CT) log search engine that queries public CT logs for any certificate issued for a given domain. Because every publicly trusted TLS certificate must be logged, crt.sh lets a penetration tester enumerate subdomains, including non-indexed or internal-looking hosts, simply by searching the domain name. This makes it the most direct and comprehensive source for SSL/TLS certificate information.

  • ✗

    Shodan

    Why it's wrong here

    Shodan is a search engine for internet-connected devices, indexing banners and service fingerprints gathered from port scans. While Shodan does display the TLS certificate presented by a host during a live scan, it does not aggregate certificate transparency logs, so it only reveals certificates for devices Shodan has recently probed. Its coverage is incomplete and not designed for domain-wide certificate enumeration.

  • ✗

    Google Dorks

    Why it's wrong here

    Google Dorks use Google's search operators to find indexed web content, such as pages, files, or exposed directories, based on patterns in the indexed text. Although dorks like site:example.com or intitle:index.of can sometimes reveal subdomains from public pages, they do not query certificate transparency logs and miss any subdomain that has never been linked or indexed. Thus, they are a general OSINT technique, not a certificate-specific source.

  • ✗

    Wayback Machine

    Why it's wrong here

    The Wayback Machine, operated by the Internet Archive, stores historical snapshots of web pages and site content over time. It does not record TLS certificate metadata, certificate issuance events, or certificate transparency entries; it only captures the HTML and assets of publicly accessible pages. As a result, it may help retrieve old subdomains from page links, but it is not a source of certificate information.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.