Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester uses Shodan to find internet-facing devices belonging to a target company. Which of the following Shodan search filters would most effectively identify devices with a specific organization name?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

org:CompanyName

The 'org' filter in Shodan allows searching by organization name, which is the most direct way to find devices associated with a company.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    hostname:company.com

    Why it's wrong here

    The hostname filter matches devices only when Shodan associates a hostname containing 'company.com' with the device, typically sourced from reverse DNS or SSL certificate subject names. Many organizational assets may be hosted on unrelated domain names, use CDN-provided hostnames, or lack any resolvable hostname entirely, so this query would miss a substantial portion of the external attack surface. Consequently, it is unreliable for comprehensive discovery.

  • ✗

    ssl:company.com

    Why it's wrong here

    The ssl filter is even more restrictive because it only returns servers whose SSL/TLS certificate content includes the string 'company.com'. Devices that do not use SSL, that present self-signed or default certificates, or that sit behind load balancers or reverse proxies managing TLS on their behalf would not appear. Additionally, the query can match unrelated certificates that merely reference the domain, introducing false positives while still omitting many legitimate company assets.

  • ✓

    org:CompanyName

    Why this is correct

    This is the correct approach because Shodan's org field is populated from IP address ownership records via regional internet registries (ARIN, RIPE, APNIC, etc.) and groups every IP address registered to the organization irrespective of hostname, certificate, or service. A penetration tester can thereby enumerate the entire internet-facing footprint of the company in one query, making org:CompanyName the definitive starting point for external reconnaissance rather than relying on incomplete metadata.

  • ✗

    net:192.168.0.0/16

    Why it's wrong here

    This filter targets RFC 1918 private address space (192.168.0.0/16), which is non-routable and never directly reachable over the public internet, so Shodan would have no data for such addresses. Even if the company uses this subnet internally, it reveals no external attack surface; a tester would instead need to identify the organization's actual public IP allocations, which may span multiple ISPs, cloud providers, and subsidiary entities, defeating the purpose of a quick search.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.