mediumMultiple ChoiceObjective-mapped
PT0-002 Practice Question: A penetration tester is using theHarvester tool…
A penetration tester is using theHarvester tool to gather information about a target domain. The tester wants to collect email addresses and subdomains from public search engines and PGP key servers. Which source is theHarvester commonly configured to use for this passive reconnaissance?
⚠ Common exam trap
Watch out — candidates often confuse passive reconnaissance with active techniques like DNS zone transfers (Option A) or assume Shodan (Option B) is a default source for theHarvester, when in fact theHarvester's core functionality relies on traditional search engines and PGP key servers for email and subdomain discovery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Google and Bing search engines
TheHarvester is specifically designed to perform passive reconnaissance by querying public search engines (like Google and Bing) and PGP key servers to collect email addresses, subdomains, and other open-source intelligence (OSINT). It does not initiate direct connections to the target's infrastructure, making it a passive tool. The default configuration often includes Google and Bing as primary sources for this data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Direct DNS zone transfer
Why it's wrong here
Direct DNS zone transfer is an active reconnaissance technique that involves sending an AXFR query directly to the target's authoritative DNS server to request a full copy of the zone. theHarvester does not perform zone transfers by default because it focuses on passive OSINT collection from third-party sources, and most modern DNS servers are configured to deny AXFR requests to untrusted hosts. Thus, while a zone transfer could expose subdomains, it is not a mechanism employed by theHarvester.
- ✗
Shodan
Why it's wrong here
Shodan is a specialized search engine for internet-connected devices, such as routers, webcams, and industrial control systems, indexing banner information and open ports. While theHarvester can integrate with Shodan's API to perform subdomain discovery, this requires explicit configuration and an API key, and Shodan is not one of the default, out-of-the-box sources that theHarvester queries. Therefore, Shodan is not the primary or typical source used by theHarvester for passive email and subdomain harvesting.
- ✗
Baidu
Why it's wrong here
Baidu is a Chinese-language web search engine, and although theHarvester has support for multiple search backends, Baidu is not commonly included in the default source list, which typically consists of Google, Bing, and PGP key servers. Furthermore, Baidu's indexing is heavily weighted toward Chinese-language content, making it less effective and less relevant for most penetration testing targets outside that region. Thus, Baidu is not a standard or expected source used by theHarvester during default passive reconnaissance.
- ✓
Google and Bing search engines
Why this is correct
TheHarvester correctly uses public search engines like Google and Bing to passively discover email addresses, subdomains, and hostnames that are publicly indexed. It queries these search engines by crafting targeted search queries, scrapes the search result pages for patterns matching email addresses and domain names, and does not interact directly with the target's infrastructure. This passive approach reduces the likelihood of detection and aligns with the OSINT phase of a penetration test, making Google and Bing the default and most commonly used sources.
Go deeper
Related to this question
Learn chapter
Penetration Testing Methodology
Key term
Passive reconnaissance
Passive reconnaissance is the process of gathering information about a target system or network without directly interacting with it, using publicly available sources and stealthy observation.
Key term
theHarvester
theHarvester is an open-source intelligence (OSINT) tool used to gather emails, subdomains, IP addresses, and other public data about a target from search engines and public sources.
About these practice questions
This PT0-003 question is part of Courseiva's 185-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.