PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester wants to query Certificate Transparency logs to find all SSL/TLS certificates issued for a target domain, which may reveal subdomains. Which tool or website is specifically designed for this purpose?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
crt.sh
crt.sh is a website that queries Certificate Transparency logs and returns certificates for a domain, often revealing subdomains. Shodan and Censys also provide certificate data but crt.sh is focused on CT logs. Let's Encrypt is a CA, not a log query tool.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
crt.sh
Why this is correct
crt.sh is a dedicated Certificate Transparency (CT) log search engine that aggregates and indexes certificates from multiple CT logs, allowing rapid lookups by domain, issuer, or serial number. It directly queries the CT framework's public, append-only logs via a web interface and API, making it the precise tool for checking which certificates have been issued for a domain, including your own. This is why it is the correct answer.
- ✗
Censys
Why it's wrong here
Censys is a general-purpose internet asset search platform that collects a wide range of host and certificate data through its own active scanning and data collection efforts. While it can display certificate information for discovered services, it is not specifically a CT log query tool; it does not index the public CT log ecosystem in the same way crt.sh does. Its primary purpose is broader asset discovery and attack surface analysis, not dedicated CT log lookups, which makes it incorrect for this specific task.
- ✗
Let's Encrypt
Why it's wrong here
Let's Encrypt is a non-profit certificate authority (CA) that issues trusted SSL/TLS certificates, not a CT log query service. Although Let's Encrypt also operates its own CT logs (such as Oak) as part of its operations, those logs are simply data sources for CT aggregators like crt.sh; the CA itself provides no user-facing query interface for searching CT logs. Therefore, it is incorrect because it is an issuer, not a CT log lookup tool.
- ✗
Shodan
Why it's wrong here
Shodan is a search engine for internet-connected devices, focusing on service banners, ports, and device metadata gathered through active internet-wide scanning. While Shodan may expose some certificate details from the HTTPS services it scans, it does not query Certificate Transparency logs and does not provide a comprehensive CT log search. Its fundamental purpose is mapping live hosts and services, not auditing the CT framework, so it fails the specific requirement of querying certificate transparency.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.