Courseiva
easyMultiple Choice

PT0-002 Practice Question: A penetration tester needs to gather information…

A penetration tester needs to gather information about a target organization's employees and email addresses from public sources. Which passive reconnaissance tool is BEST suited for this task?

⚠ Common exam trap

A common mix-up: candidates confuse active scanning tools (like Nikto or Nmap) with passive reconnaissance, failing to recognize that Maltego is specifically designed for OSINT gathering from public sources without sending probes to the target.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Maltego

Maltego is a passive reconnaissance tool that excels at gathering information from public sources, including employee names, email addresses, and organizational relationships, by querying open-source intelligence (OSINT) data such as social media, search engines, and DNS records. It uses transforms to automate data collection and link analysis, making it ideal for this task without directly interacting with the target's systems.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Nikto

    Why it's wrong here

    Nikto is an active web server vulnerability scanner that sends a battery of crafted HTTP requests to a target URL, checking for known dangerous files, outdated server software, and configuration problems. Its purpose is to audit a live web server, not to passively harvest public OSINT from open sources; running it during an information-gathering phase would create direct, logged network traffic and could alert the target, making it unsuitable for the described OSINT-style email/employee discovery task.

  • ✗

    Nmap

    Why it's wrong here

    Nmap is a network mapping and port-scanning tool that actively transmits raw IP packets to discover hosts, open ports, and running services on a reachable network. It requires the target's IP address or hostname and direct network connectivity, and its probes are easily detectable by intrusion detection systems, so it does not help gather passive public information such as employee emails nor does it fit a pure OSINT information-gathering phase. Nmap's value is in active infrastructure enumeration, not in mining public records and social media.

  • ✗

    Wireshark

    Why it's wrong here

    Wireshark is a protocol analyzer that captures and inspects live packets as they traverse a local network interface, relying on access to network traffic (e.g., from a sniffing position or a switched network with port mirroring). It does not query external OSINT sources, and without an existing data stream from the target it yields no email addresses or employee details from public websites; furthermore, capturing traffic on a network without authorization raises legal and ethical issues, so it is not the correct tool for open-source information gathering about a remote target.

  • ✓

    Maltego

    Why this is correct

    Maltego is an OSINT and data-mining platform that uses transforms to query public data sources—DNS records, document metadata, social media, search engines, and breach databases—then visually links entities to reveal relationships. It is designed for passive reconnaissance and relationship mapping, making it the right choice for gathering email addresses and employee information about a target without interacting with the target's own infrastructure. The tool's graph-based analysis lets a tester pivot from an organization name to individuals, roles, and associated domains, which is exactly the stated task.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Go deeper

Related to this question

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.