PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester uses Shodan to find internet-facing devices belonging to a target company. Which of the following Shodan search filters would most effectively identify devices with a specific organization name?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
org:CompanyName
The 'org' filter in Shodan allows searching by organization name, which is the most direct way to find devices associated with a company.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
hostname:company.com
Why it's wrong here
The hostname filter matches devices only when Shodan associates a hostname containing 'company.com' with the device, typically sourced from reverse DNS or SSL certificate subject names. Many organizational assets may be hosted on unrelated domain names, use CDN-provided hostnames, or lack any resolvable hostname entirely, so this query would miss a substantial portion of the external attack surface. Consequently, it is unreliable for comprehensive discovery.
- ✗
ssl:company.com
Why it's wrong here
The ssl filter is even more restrictive because it only returns servers whose SSL/TLS certificate content includes the string 'company.com'. Devices that do not use SSL, that present self-signed or default certificates, or that sit behind load balancers or reverse proxies managing TLS on their behalf would not appear. Additionally, the query can match unrelated certificates that merely reference the domain, introducing false positives while still omitting many legitimate company assets.
- ✓
org:CompanyName
Why this is correct
This is the correct approach because Shodan's org field is populated from IP address ownership records via regional internet registries (ARIN, RIPE, APNIC, etc.) and groups every IP address registered to the organization irrespective of hostname, certificate, or service. A penetration tester can thereby enumerate the entire internet-facing footprint of the company in one query, making org:CompanyName the definitive starting point for external reconnaissance rather than relying on incomplete metadata.
- ✗
net:192.168.0.0/16
Why it's wrong here
This filter targets RFC 1918 private address space (192.168.0.0/16), which is non-routable and never directly reachable over the public internet, so Shodan would have no data for such addresses. Even if the company uses this subnet internally, it reveals no external attack surface; a tester would instead need to identify the organization's actual public IP allocations, which may span multiple ISPs, cloud providers, and subsidiary entities, defeating the purpose of a quick search.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.