easyMultiple Choice
PT0-002 Practice Question: A penetration tester is tasked with performing…
A penetration tester is tasked with performing passive reconnaissance against a client without triggering any alerts. Which of the following techniques would be MOST appropriate?
⚠ Common exam trap
Candidates often confuse passive reconnaissance with low-and-slow active techniques, assuming that a single SYN scan or banner grab is 'quiet enough' to avoid detection, but any packet sent to the target is active and can be logged.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Shodan search
Shodan is a search engine that indexes banners from internet-facing devices, allowing a penetration tester to gather information about a client's exposed services (e.g., open ports, software versions) without sending any packets to the target. This makes it a purely passive technique that will not trigger any alerts on the client's network or intrusion detection systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Nmap SYN scan
Why it's wrong here
An Nmap SYN scan ( -sS ) is definitively active reconnaissance because it transmits specially crafted TCP SYN packets directly to the target host and analyzes the responses (SYN-ACK, RST, or no reply) to infer open ports and service states. This probe generates live network traffic that can be detected by intrusion detection systems, firewall logs, and the target's own packet capture, violating the fundamental passive-recon requirement of not touching the target. Even with stealth options like idle scans or decoys, the technique inherently requires sending packets, so it cannot be classified as passive.
- ✓
Shodan search
Why this is correct
A Shodan search is a canonical passive reconnaissance technique because it queries Shodan's pre-existing database of internet-facing device banners, service metadata, and open ports that Shodan has already collected through its own scanning infrastructure. The penetration tester never sends a packet directly to the target; instead, they retrieve historical and current exposure data from Shodan's indexed records, making it both non-intrusive and largely undetectable by the target. This approach also reveals information such as default credentials, SSL certificate details, and exposed industrial control systems without any active interaction.
- ✗
Brute-force login
Why it's wrong here
Brute-force login is inherently active and intrusive because the tester establishes repeated application-level or protocol-level authentication attempts against the target service, each of which sends requests over the network and is logged by the target's authentication subsystem and security monitoring. This technique generates a measurable traffic footprint, increases the risk of account lockouts, and triggers alerting on failed-login thresholds, and it often violates authorization boundaries if credentials are guessed aggressively. Moreover, brute-forcing requires direct interaction with the live target, which is the exact opposite of passive recon's goal of gathering information without the target's knowledge.
- ✗
Netcat banner grab
Why it's wrong here
Netcat banner grab is an active technique because the tester opens a TCP or UDP connection to a specific port on the target and sends a payload (such as a newline or an HTTP request) to solicit a banner response from the service. That outgoing connection and the received banner constitute direct, live interaction with the target, producing traces in connection logs, netflow records, and the service's own logging—again, detectable and not passive. Even a simple 'nc target 80' followed by a manual ENTER to trigger an HTTP response remains an active handshake, unlike querying a third-party database like Shodan.
Go deeper
Related to this question
Learn chapter
Lateral Movement Techniques
Key term
Shodan
Shodan is a search engine that lets you find specific types of internet-connected devices, such as webcams, routers, and servers, by scanning the internet and indexing their services and banners.
Key term
Passive reconnaissance
Passive reconnaissance is the process of gathering information about a target system or network without directly interacting with it, using publicly available sources and stealthy observation.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.