Courseiva
mediumMultiple ChoiceObjective-mapped

PT0-002 Practice Question: A penetration tester is using theHarvester tool…

A penetration tester is using theHarvester tool to gather information about a target domain. The tester wants to collect email addresses and subdomains from public search engines and PGP key servers. Which source is theHarvester commonly configured to use for this passive reconnaissance?

⚠ Common exam trap

Watch out — candidates often confuse passive reconnaissance with active techniques like DNS zone transfers (Option A) or assume Shodan (Option B) is a default source for theHarvester, when in fact theHarvester's core functionality relies on traditional search engines and PGP key servers for email and subdomain discovery.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Google and Bing search engines

TheHarvester is specifically designed to perform passive reconnaissance by querying public search engines (like Google and Bing) and PGP key servers to collect email addresses, subdomains, and other open-source intelligence (OSINT). It does not initiate direct connections to the target's infrastructure, making it a passive tool. The default configuration often includes Google and Bing as primary sources for this data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Direct DNS zone transfer

    Why it's wrong here

    Direct DNS zone transfer is an active reconnaissance technique that involves sending an AXFR query directly to the target's authoritative DNS server to request a full copy of the zone. theHarvester does not perform zone transfers by default because it focuses on passive OSINT collection from third-party sources, and most modern DNS servers are configured to deny AXFR requests to untrusted hosts. Thus, while a zone transfer could expose subdomains, it is not a mechanism employed by theHarvester.

  • Shodan

    Why it's wrong here

    Shodan is a specialized search engine for internet-connected devices, such as routers, webcams, and industrial control systems, indexing banner information and open ports. While theHarvester can integrate with Shodan's API to perform subdomain discovery, this requires explicit configuration and an API key, and Shodan is not one of the default, out-of-the-box sources that theHarvester queries. Therefore, Shodan is not the primary or typical source used by theHarvester for passive email and subdomain harvesting.

  • Baidu

    Why it's wrong here

    Baidu is a Chinese-language web search engine, and although theHarvester has support for multiple search backends, Baidu is not commonly included in the default source list, which typically consists of Google, Bing, and PGP key servers. Furthermore, Baidu's indexing is heavily weighted toward Chinese-language content, making it less effective and less relevant for most penetration testing targets outside that region. Thus, Baidu is not a standard or expected source used by theHarvester during default passive reconnaissance.

  • Google and Bing search engines

    Why this is correct

    TheHarvester correctly uses public search engines like Google and Bing to passively discover email addresses, subdomains, and hostnames that are publicly indexed. It queries these search engines by crafting targeted search queries, scrapes the search result pages for patterns matching email addresses and domain names, and does not interact directly with the target's infrastructure. This passive approach reduces the likelihood of detection and aligns with the OSINT phase of a penetration test, making Google and Bing the default and most commonly used sources.

Go deeper

Related to this question

About these practice questions

This PT0-003 question is part of Courseiva's 185-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.