easyMultiple Choice
PT0-002 Practice Question: A penetration tester wants to discover subdomains…
A penetration tester wants to discover subdomains of a target domain without sending any packets directly to the target's network. Which resource is most effective for this purpose?
⚠ Common exam trap
CompTIA often tests the distinction between active and passive reconnaissance; the trap here is assuming DNS brute force is passive because it uses a wordlist, but it actively queries DNS servers, whereas CT logs are truly passive as they rely on publicly archived certificate data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Certificate Transparency logs
Certificate Transparency (CT) logs are publicly accessible, append-only ledgers that record every SSL/TLS certificate issued by a Certificate Authority (CA). Since certificates often include Subject Alternative Names (SANs) listing subdomains, querying CT logs (e.g., via crt.sh or tools like `certigo`) reveals subdomains without any direct network probes. This makes CT logs the most effective passive reconnaissance resource, as no packets are sent to the target's infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS brute force with a wordlist
Why it's wrong here
DNS brute force with a wordlist involves sending numerous DNS lookup queries for potential subdomain names derived from a wordlist to the target's authoritative nameservers. This is a form of active reconnaissance because it generates network traffic that can be observed and logged by the target or its DNS provider, raising the risk of detection. While it can find subdomains, it is noisy, time-consuming, and may be throttled, making it less desirable when passive sources like Certificate Transparency are available.
- ✓
Certificate Transparency logs
Why this is correct
Certificate Transparency logs are public, auditable records of every SSL/TLS certificate issued by participating certificate authorities. By querying these logs for the target domain (e.g., via crt.sh or the official CT API), a tester can retrieve a comprehensive list of subdomains that have had certificates issued, including historical ones. This is passive reconnaissance because it uses third-party data without sending any packets to the target, making it stealthy and highly effective.
- ✗
WHOIS lookup
Why it's wrong here
WHOIS lookup returns ownership and administrative information for a registered domain, such as the registrant's name, email, and authoritative name servers. This data comes from the domain registrar's WHOIS server, not from DNS zone data, so it does not list a domain's subdomains or host records. Although useful for OSINT and social engineering, it is not a subdomain discovery technique because it lacks any mechanism to enumerate DNS-level resource records.
- ✗
Traceroute
Why it's wrong here
Traceroute maps the network path to a known IP address by sending packets with incrementing TTL values and recording ICMP or UDP responses from each router hop. It requires a specific IP or hostname to trace; it cannot generate a list of subdomains because it never queries DNS for domain resource records. Additionally, it actively sends traffic toward the target, so it is both irrelevant for subdomain discovery and another form of active reconnaissance that could tip off defenders.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.