PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is using theHarvester to gather email addresses associated with a target domain. The tool returns several email addresses. What is the primary limitation of using theHarvester for this purpose?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It only finds publicly available email addresses
theHarvester collects data from public sources, so its results are limited to what is publicly available. It may miss internal email addresses and can include outdated information. It does not require authentication, and it is not limited to Google only.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It requires authentication to the target's mail server
Why it's wrong here
theHarvester is a passive OSINT tool that queries publicly accessible search engines, PGP key servers, and other internet data sources. It never connects to the target's mail server directly, so no authentication to that server is required. Requiring credentials would make it an active attack tool, which contradicts its purpose of unauthenticated reconnaissance.
- ✗
It only searches Google
Why it's wrong here
While Google is one of its default sources, theHarvester is designed to aggregate data from many public search engines and APIs, including Bing, Yahoo, Baidu, DuckDuckGo, Exalead, Shodan, and PGP key servers. This multi-source approach increases coverage and helps bypass the rate limits or partial results that a single engine like Google would impose. The claim that it only searches Google is therefore factually incorrect.
- ✓
It only finds publicly available email addresses
Why this is correct
This is correct because theHarvester is an open-source intelligence (OSINT) tool that collects email addresses from publicly indexed web pages, PGP keys, and other exposed data. It cannot penetrate internal directories, address books, or private mail servers, so emails that are never published online won't be discovered. The result set is limited to those addresses that the target or third parties have intentionally or accidentally made public.
- ✗
It cannot find subdomains
Why it's wrong here
theHarvester explicitly supports subdomain enumeration as a core feature; its -d and -b flags allow you to specify a domain and a data source, and it returns subdomains found across search engines, certificate transparency logs, and PGP key databases. In practice, this helps penetration testers map the attack surface beyond the root domain. Thus, saying it cannot find subdomains is false, as the tool routinely discovers them during reconnaissance.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.