Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester wants to use Google dorking to find publicly accessible documents containing sensitive information on a target domain 'example.com'. Which Google dork would be MOST appropriate to locate PDF files with the word 'confidential'?

⚠ Common exam trap

Candidates often confuse 'filetype:pdf' with 'inurl:pdf' or 'intitle:pdf', not realizing that 'filetype' specifically filters by file extension, while 'inurl' and 'intitle' search for text in the URL or title, which may not correspond to actual PDF files.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

site:example.com filetype:pdf confidential

The Google dork 'site:example.com filetype:pdf confidential' combines the site restriction to the target domain, the filetype filter for PDFs, and the keyword 'confidential' to search for PDF documents containing that word. This directly matches the requirement to locate publicly accessible PDF files with the word 'confidential' on example.com.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    site:example.com intitle:confidential pdf

    Why it's wrong here

    The intitle: operator restricts results to pages where the term appears in the HTML <title> tag, not within the body or text of a PDF file. Additionally, the bare token 'pdf' is treated as a regular keyword matching any occurrence of the string 'pdf' on the page, not as a file extension filter. Consequently, this query returns HTML pages with 'confidential' in the title and the word 'pdf' somewhere, rather than actual PDF documents containing confidential content.

  • ✗

    filetype:pdf site:example.com password

    Why it's wrong here

    This dork correctly uses filetype:pdf to limit results to indexed PDF files and site:example.com to scope to the target domain, but the search term 'password' is the focus of the content query. Since the penetration tester is seeking documents labeled 'confidential,' using 'password' as the keyword will retrieve PDFs that discuss credentials or login procedures, completely missing the intended confidential files. The operator syntax is valid, but the keyword choice does not align with the objective.

  • ✓

    site:example.com filetype:pdf confidential

    Why this is correct

    This is the correct Google dork for the objective. The site:example.com operator confines results to the target domain, filetype:pdf restricts results to PDF files, and the standalone keyword 'confidential' matches pages where that term appears within the indexed text of the PDF. Search engines like Google extract and index text content from PDFs, so this query effectively surfaces PDF documents on example.com that contain the word 'confidential,' which is exactly what a penetration tester would want to find during reconnaissance.

  • ✗

    site:example.com inurl:pdf confidential

    Why it's wrong here

    The inurl:pdf operator only requires that the string 'pdf' appears somewhere in the URL, such as in a folder name (/pdf/), a query parameter (?id=pdf), or an HTML file like pdf-index.php. Even if the URL contains 'pdf', the actual content could be an HTML page, an image, or another file type, and the term 'confidential' would be searched across all those indexed pages. To reliably target PDF files, the correct operator is filetype:pdf, which filters by the file's extension and content type, not by URL substring matching.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.