PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is reviewing SSL/TLS certificate information for a target domain and wants to discover additional subdomains that share the same certificate. Which resource is best for this purpose?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
crt.sh
Certificate Transparency logs (e.g., crt.sh) allow searching by domain or certificate fingerprint to find all certificates issued for that domain, often revealing subdomains.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
crt.sh
Why this is correct
crt.sh is a certificate transparency (CT) log search engine that queries public CT logs for any certificate issued for a given domain. Because every publicly trusted TLS certificate must be logged, crt.sh lets a penetration tester enumerate subdomains, including non-indexed or internal-looking hosts, simply by searching the domain name. This makes it the most direct and comprehensive source for SSL/TLS certificate information.
- ✗
Shodan
Why it's wrong here
Shodan is a search engine for internet-connected devices, indexing banners and service fingerprints gathered from port scans. While Shodan does display the TLS certificate presented by a host during a live scan, it does not aggregate certificate transparency logs, so it only reveals certificates for devices Shodan has recently probed. Its coverage is incomplete and not designed for domain-wide certificate enumeration.
- ✗
Google Dorks
Why it's wrong here
Google Dorks use Google's search operators to find indexed web content, such as pages, files, or exposed directories, based on patterns in the indexed text. Although dorks like site:example.com or intitle:index.of can sometimes reveal subdomains from public pages, they do not query certificate transparency logs and miss any subdomain that has never been linked or indexed. Thus, they are a general OSINT technique, not a certificate-specific source.
- ✗
Wayback Machine
Why it's wrong here
The Wayback Machine, operated by the Internet Archive, stores historical snapshots of web pages and site content over time. It does not record TLS certificate metadata, certificate issuance events, or certificate transparency entries; it only captures the HTML and assets of publicly accessible pages. As a result, it may help retrieve old subdomains from page links, but it is not a source of certificate information.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.