Courseiva
easyMultiple Choice

PT0-002 Practice Question: A penetration tester is tasked with performing…

A penetration tester is tasked with performing passive reconnaissance against a client without triggering any alerts. Which of the following techniques would be MOST appropriate?

⚠ Common exam trap

Candidates often confuse passive reconnaissance with low-and-slow active techniques, assuming that a single SYN scan or banner grab is 'quiet enough' to avoid detection, but any packet sent to the target is active and can be logged.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Shodan search

Shodan is a search engine that indexes banners from internet-facing devices, allowing a penetration tester to gather information about a client's exposed services (e.g., open ports, software versions) without sending any packets to the target. This makes it a purely passive technique that will not trigger any alerts on the client's network or intrusion detection systems.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Nmap SYN scan

    Why it's wrong here

    An Nmap SYN scan ( -sS ) is definitively active reconnaissance because it transmits specially crafted TCP SYN packets directly to the target host and analyzes the responses (SYN-ACK, RST, or no reply) to infer open ports and service states. This probe generates live network traffic that can be detected by intrusion detection systems, firewall logs, and the target's own packet capture, violating the fundamental passive-recon requirement of not touching the target. Even with stealth options like idle scans or decoys, the technique inherently requires sending packets, so it cannot be classified as passive.

  • ✓

    Shodan search

    Why this is correct

    A Shodan search is a canonical passive reconnaissance technique because it queries Shodan's pre-existing database of internet-facing device banners, service metadata, and open ports that Shodan has already collected through its own scanning infrastructure. The penetration tester never sends a packet directly to the target; instead, they retrieve historical and current exposure data from Shodan's indexed records, making it both non-intrusive and largely undetectable by the target. This approach also reveals information such as default credentials, SSL certificate details, and exposed industrial control systems without any active interaction.

  • ✗

    Brute-force login

    Why it's wrong here

    Brute-force login is inherently active and intrusive because the tester establishes repeated application-level or protocol-level authentication attempts against the target service, each of which sends requests over the network and is logged by the target's authentication subsystem and security monitoring. This technique generates a measurable traffic footprint, increases the risk of account lockouts, and triggers alerting on failed-login thresholds, and it often violates authorization boundaries if credentials are guessed aggressively. Moreover, brute-forcing requires direct interaction with the live target, which is the exact opposite of passive recon's goal of gathering information without the target's knowledge.

  • ✗

    Netcat banner grab

    Why it's wrong here

    Netcat banner grab is an active technique because the tester opens a TCP or UDP connection to a specific port on the target and sends a payload (such as a newline or an HTTP request) to solicit a banner response from the service. That outgoing connection and the received banner constitute direct, live interaction with the target, producing traces in connection logs, netflow records, and the service's own logging—again, detectable and not passive. Even a simple 'nc target 80' followed by a manual ENTER to trigger an HTTP response remains an active handshake, unlike querying a third-party database like Shodan.

Go deeper

Related to this question

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.