Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is using Shodan to identify internet-facing devices associated with a target organization. Which of the following is Shodan's primary function in the context of passive reconnaissance?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Searching for devices and services exposed to the internet

Shodan is a search engine for internet-connected devices, providing information about services and banners. It does not perform active scans itself; it indexes data from active scanning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Analyzing malware samples

    Why it's wrong here

    Shodan is an internet device search engine that catalogs banner data and service fingerprints from publicly reachable IPs; it does not receive, execute, or analyze malware binaries. Malware analysis typically requires a sandbox or disassembler to inspect code behavior, not a network index. Therefore, using Shodan for this purpose is incorrect.

  • ✗

    Exploiting vulnerabilities in IoT devices

    Why it's wrong here

    While Shodan can reveal IoT devices with known default credentials or outdated firmware (e.g., exposed cameras or routers), it only surfaces information from banners and protocol handshakes; it does not actively attempt to compromise devices or run exploit code. Penetration testers might use Shodan to find targets, but exploitation is performed with separate tools like Metasploit or custom scripts. So the statement that Shodan itself exploits is wrong.

  • ✓

    Searching for devices and services exposed to the internet

    Why this is correct

    Shodan continuously probes public IP ranges and collects response banners, including HTTP headers, SSH keys, and SNMP strings, which it indexes for instant querying. This enables a pen tester to identify specific device types, software versions, and open ports on a global scale, making it an invaluable reconnaissance tool prior to close-in testing. It allows searching by filter such as 'port:22', 'product:Apache', or 'country:US'.

  • ✗

    Performing live port scans on target IPs

    Why it's wrong here

    Shodan does not offer on-demand scanning of arbitrary targets; its database is built from its own scheduled, global scanning campaigns. If a pen tester needs real-time port state or service version information for a specific IP, they must use tools like Nmap directly, which conduct active scans. Thus, Shodan acts as a historical index rather than a live scanning tool.

Go deeper

Related to this question

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.