PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is using Shodan to identify internet-facing devices associated with a target organization. Which of the following is Shodan's primary function in the context of passive reconnaissance?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Searching for devices and services exposed to the internet
Shodan is a search engine for internet-connected devices, providing information about services and banners. It does not perform active scans itself; it indexes data from active scanning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Analyzing malware samples
Why it's wrong here
Shodan is an internet device search engine that catalogs banner data and service fingerprints from publicly reachable IPs; it does not receive, execute, or analyze malware binaries. Malware analysis typically requires a sandbox or disassembler to inspect code behavior, not a network index. Therefore, using Shodan for this purpose is incorrect.
- ✗
Exploiting vulnerabilities in IoT devices
Why it's wrong here
While Shodan can reveal IoT devices with known default credentials or outdated firmware (e.g., exposed cameras or routers), it only surfaces information from banners and protocol handshakes; it does not actively attempt to compromise devices or run exploit code. Penetration testers might use Shodan to find targets, but exploitation is performed with separate tools like Metasploit or custom scripts. So the statement that Shodan itself exploits is wrong.
- ✓
Searching for devices and services exposed to the internet
Why this is correct
Shodan continuously probes public IP ranges and collects response banners, including HTTP headers, SSH keys, and SNMP strings, which it indexes for instant querying. This enables a pen tester to identify specific device types, software versions, and open ports on a global scale, making it an invaluable reconnaissance tool prior to close-in testing. It allows searching by filter such as 'port:22', 'product:Apache', or 'country:US'.
- ✗
Performing live port scans on target IPs
Why it's wrong here
Shodan does not offer on-demand scanning of arbitrary targets; its database is built from its own scheduled, global scanning campaigns. If a pen tester needs real-time port state or service version information for a specific IP, they must use tools like Nmap directly, which conduct active scans. Thus, Shodan acts as a historical index rather than a live scanning tool.
Go deeper
Related to this question
Learn chapter
CVSS Scoring in Penetration Test Reports
Key term
Passive reconnaissance
Passive reconnaissance is the process of gathering information about a target system or network without directly interacting with it, using publicly available sources and stealthy observation.
Key term
Shodan
Shodan is a search engine that lets you find specific types of internet-connected devices, such as webcams, routers, and servers, by scanning the internet and indexing their services and banners.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.