Courseiva

PT0-003 · domain

Reconnaissance and Enumeration

Reconnaissance and Enumeration covers passive and active information gathering before exploitation: OSINT, DNS and subdomain discovery, host discovery, service and version detection, and web content discovery. Questions present a scenario and ask you to pick the correct technique, tool, or command, or to distinguish passive methods from those that touch the target's infrastructure.

99 questions24 easy47 medium28 hard

Focused practice

Practice Reconnaissance and Enumeration questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Reconnaissance and Enumeration

Be able to classify a technique as passive or active, choose the right tool for OSINT versus DNS versus web enumeration, and write correct Nmap syntax. The key skill is knowing whether your action sends traffic to the target, since that decides the technique and tool.

Passive subdomain discovery via certificate transparency logs, DNS aggregators, and search engines without querying target servers

OSINT tooling such as theHarvester, Maltego, and Shodan for employees, emails, and infrastructure

Web content discovery using directory brute-forcing tools like Gobuster, Dirb, and Feroxbuster

Nmap host discovery with -sn to find live hosts without port scanning

Watch out for

Common Reconnaissance and Enumeration exam traps

  • ▸Treating active DNS queries or zone transfers as passive; any query to the target's nameservers generates traffic and is active reconnaissance
  • ▸Confusing host discovery (-sn) with port scanning; -sn only pings and does not enumerate open ports or services
  • ▸Assuming directory brute-forcing is passive; it sends requests to the target web server and is noisy, detectable active enumeration

Question index

All Reconnaissance and Enumeration questions (99)

Click any question to see the full explanation, or start a practice session above.

1

A penetration tester wants to query Certificate Transparency logs to find all SSL/TLS certificates issued for a target domain, which may reveal subdomains. Which tool or website is specifically designed for this purpose?

Easy
2

Which tool is specifically designed for scanning WordPress websites to detect vulnerabilities, such as outdated plugins, themes, and weak passwords?

Easy
3

A tester is scanning a target network using Nmap. The client wants minimal disruption and asks to avoid completing TCP three-way handshakes. Which scan type should the tester use?

Medium
4

A penetration tester is analyzing a web application's JavaScript files for hardcoded secrets and API endpoints. Which THREE techniques or tools are MOST effective for this purpose? (Select THREE.)

Hard
5

A penetration tester is conducting passive reconnaissance on a target organization. Which of the following tools is specifically designed for gathering OSINT by extracting email addresses, subdomains, and employee names from public sources?

Easy
6

During a penetration test, you are asked to discover all live hosts on a subnet without generating excessive traffic or being too intrusive. Which Nmap command best achieves this goal?

Medium
7

A penetration tester is performing passive reconnaissance on a target organization. Which of the following tools would be BEST suited to gather information about the organization's domain names, email addresses, and subdomains from publicly available sources without directly interacting with the target's systems?

Medium
8

During a penetration test, the tester wants to identify live hosts on a network without performing a full port scan. Which Nmap command is most appropriate for this task?

Easy
9

During a penetration test, the tester wants to gather information about the target organization's domain registration and contact details without sending any traffic to the target. Which OSINT source should the tester use first?

Easy
10

During a penetration test, the tester runs a DNS zone transfer attempt against a target domain. The zone transfer fails. What is the most likely reason?

Hard
11

During a penetration test, you want to perform a stealthy port scan that minimizes the chance of being logged by the target. Which Nmap option should you use?

Medium
12

During a penetration test, you need to gather information about a target's email addresses and employee names without directly interacting with the target's systems. Which tool is most appropriate for this passive reconnaissance task?

Medium
13

During an external penetration test, a tester needs to enumerate DNS records for a target domain to identify mail servers and potential subdomains. The tester has no credentials and wants to use a tool that queries DNS servers directly. Which tool is most appropriate for this task?

Easy
14

During a penetration test, you want to discover API endpoints and hidden parameters in a web application. Which tool combination is most effective for this task?

Hard
15

A penetration tester is performing passive reconnaissance on a target organization. Which of the following tools would be BEST for discovering subdomains and email addresses associated with the target domain without sending any packets to the target?

Easy
16

While performing vulnerability scanning, a penetration tester runs a Nessus scan against a web server. The report shows a 'critical' finding, but after manual verification, the tester determines the service is not actually vulnerable. This scenario best describes:

Medium
17

A penetration tester is conducting active reconnaissance on a target network and wants to enumerate SNMP information. Which TWO of the following tools or commands can be used to query SNMP data from network devices? (Select TWO.)

Hard
18

During a penetration test, the tester runs an Nmap scan with the -sV option and gets a result showing 'Apache httpd 2.4.49'. This version is known to be vulnerable to a path traversal attack. Which of the following best describes the next step the tester should take?

Hard
19

You are performing a vulnerability scan on a web application and notice that the scanner reports a high-severity SQL injection vulnerability. However, manual testing confirms that the input is properly sanitized. Which term best describes this situation?

Hard
20

A penetration tester is tasked with performing an authenticated vulnerability scan of a Windows network. The tester has domain admin credentials. Which tool is most appropriate for this task?

Hard
21

A penetration tester wants to perform passive reconnaissance on a target organization. Which two activities are considered passive reconnaissance? (Choose TWO.)

Easy
22

A penetration tester is conducting a web application reconnaissance and wants to discover API endpoints and hidden parameters. Which three tools are most appropriate for this task? (Choose THREE.)

Medium
23

You are performing a network scan and need to identify live hosts on a subnet without triggering firewalls that block ICMP. Which technique should you use?

Medium
24

You are conducting a penetration test and need to identify subdomains of a target domain using a passive approach that does not generate traffic to the target's servers. Which technique should you use?

Medium
25

During a penetration test, a tester uses the Wayback Machine to review historical versions of the target's website. What is the primary benefit of this activity?

Hard
26

A penetration tester is conducting passive reconnaissance and wants to gather information about a target organization's employees, email addresses, and internal structure. Which TWO tools are best suited for this purpose? (Select TWO.)

Medium
27

You are performing reconnaissance on a target's web application. Which of the following techniques can be used to discover hidden directories and files? (Select THREE.)

Hard
28

While performing vulnerability scanning with Nessus, a penetration tester notices that several high-severity vulnerabilities are reported for a web server, but manual verification shows the server is not vulnerable. What is the MOST likely cause of this discrepancy?

Medium
29

During the information gathering phase, a penetration tester uses Google dorks to find exposed documents on a target's website. Which Google dork would be most appropriate to find PDF files containing sensitive information?

Easy
30

A penetration tester is performing a vulnerability scan on a web server using Nikto. After the scan, the tester notices several findings related to outdated software versions and missing security headers. What should the tester do to validate the findings and reduce false positives?

Easy
31

A penetration tester is analyzing a web application and wants to discover hidden API endpoints by brute-forcing common paths. Which tool is best suited for this task?

Hard
32

A penetration tester is using Shodan to identify internet-facing devices associated with a target organization. Which of the following is Shodan's primary function in the context of passive reconnaissance?

Medium
33

Which Nmap scan type sends SYN packets to determine open ports without completing the TCP three-way handshake?

Easy
34

You are conducting passive reconnaissance on a target organization. Which of the following are examples of passive reconnaissance techniques? (Select TWO.)

Easy
35

A penetration tester is performing reconnaissance against a target organization and must passively collect email addresses, employee names, and document metadata without directly interacting with the target's servers. Which tool or technique is best suited for this requirement?

Medium
36

A penetration tester is conducting active reconnaissance and wants to perform a SYN scan on a target network. During the scan, the tester notices that some ports are reported as filtered. What does a filtered port status typically indicate in Nmap?

Hard
37

A penetration tester is performing internal network scanning and wants to identify live hosts on a local subnet without sending IP packets. Which method is most effective in a switched Ethernet environment?

Hard
38

A penetration tester is conducting a web application assessment and discovers that the target uses WordPress. The tester wants to identify installed plugins, themes, and potential vulnerabilities. Which of the following tools is best suited for this task?

Hard
39

A penetration tester is conducting passive reconnaissance on a target organization. The tester wants to discover subdomains and associated email addresses without directly interacting with the target's infrastructure. Which combination of tools and sources would be most effective for this task?

Medium
40

A penetration tester is using Nmap to perform an aggressive scan of a target. Which command combines OS detection, version detection, script scanning, and traceroute?

Medium
41

During a penetration test, the tester is using Gobuster to enumerate directories on a web server. Which flag would the tester use to specify a list of file extensions to append to each word in the wordlist for discovering files like 'admin.php' or 'config.bak'?

Medium
42

A penetration tester is conducting a vulnerability scan on a web server using Nikto. The scan report lists several findings, including a directory listing vulnerability and outdated server headers. Which type of scanner is Nikto?

Easy
43

A penetration tester is reviewing SSL/TLS certificate information for a target domain and wants to discover additional subdomains that share the same certificate. Which resource is best for this purpose?

Hard
44

A penetration tester is performing a security assessment of a network that uses SNMP. The tester successfully connects to a device using the community string 'public'. Which tool would the tester MOST likely use to enumerate the entire Management Information Base (MIB) tree to extract system information, running processes, and network interfaces?

Hard
45

A penetration tester is using Nmap to perform host discovery on a target network 192.168.1.0/24. The tester wants to identify live hosts without scanning ports. Which Nmap command should be used?

Medium
46

During the information gathering phase, a penetration tester wants to discover subdomains of a target domain using DNS queries and potentially brute-forcing common subdomain names. Which of the following tools is specifically designed for subdomain enumeration and can perform both passive and active techniques?

Easy
47

A penetration tester has discovered a web application that appears to be built with WordPress. The tester wants to identify installed plugins, themes, and potential vulnerabilities without triggering intrusion detection systems. Which tool is BEST suited for this task?

Hard
48

A penetration tester uses Shodan to find internet-facing devices belonging to a target company. Which of the following Shodan search filters would most effectively identify devices with a specific organization name?

Hard
49

A penetration tester is using theHarvester to gather email addresses associated with a target domain. The tool returns several email addresses. What is the primary limitation of using theHarvester for this purpose?

Medium
50

A penetration tester is assessing a web application and wants to identify hidden parameters that the application accepts. Which tool is specifically designed for parameter discovery?

Hard
51

A penetration tester is conducting passive reconnaissance and wants to find historical snapshots of a target website to identify past vulnerabilities or hidden endpoints. Which online service should the tester use?

Easy
52

During a penetration test, you find a web application that uses JavaScript to make API calls. You want to discover hidden API endpoints and potential secrets (e.g., API keys) embedded in the client-side code. Which approach is most appropriate?

Hard
53

Which of the following tools would best assist a penetration tester in identifying known vulnerabilities in a WordPress installation?

Easy
54

A penetration tester is performing active reconnaissance on a target network and wants to enumerate SNMP devices to gather system information. The tester uses snmpwalk with a common community string. Which community string is most likely to provide read-write access if misconfigured?

Hard
55

During a penetration test, the tester performs a SYN scan with Nmap on a target network. The results show that port 443 is open on a web server. The tester then runs a service version detection scan and discovers the server is running Apache 2.4.41. Which Nmap flags were used in sequence?

Medium
56

A penetration tester is enumerating SMB shares on a Windows host during an internal assessment. The tester has valid domain credentials for a low-privileged user and wants to list shares and identify accessible files without triggering account lockouts. Which tool and approach is most appropriate?

Hard
57

During a penetration test, a tester discovers a web application that uses JavaScript to load API endpoints dynamically. Which technique would be most effective for discovering hidden API endpoints?

Medium
58

Which of the following tools is most commonly used for passive reconnaissance by querying certificate transparency logs to discover subdomains?

Easy
59

A penetration tester is performing active reconnaissance on a target web application. Which TWO tools are specifically designed for directory and file enumeration? (Select TWO.)

Medium
60

A penetration tester is tasked with performing active reconnaissance on an internal network. The tester wants to identify live hosts and their open ports efficiently while minimizing noise. Which Nmap scan type should be used first to quickly discover which hosts are online?

Medium
61

You are performing a vulnerability scan on an internal network using an authenticated scanner. Which of the following is a primary benefit of authenticated scanning compared to unauthenticated scanning?

Medium
62

A penetration tester is performing active reconnaissance on a web application and wants to discover hidden directories and files. Which tool would be most effective for brute-forcing directory names based on a wordlist?

Medium
63

A penetration tester is performing host discovery on a subnet. Which TWO of the following Nmap options can be used to discover live hosts?

Medium
64

A penetration tester is performing DNS reconnaissance and wants to enumerate all subdomains of a target domain by querying DNS servers in an attempt to transfer the entire zone file. Which technique is the tester using?

Medium
65

A penetration tester is using Nmap to identify the operating system of a target host. Which Nmap option should be used to enable OS detection?

Medium
66

A penetration tester wants to perform a directory brute-force attack against a web server to discover hidden files and directories. Which tool is best suited for this task?

Medium
67

A penetration tester is analyzing the output of a Nessus vulnerability scan and notices a critical vulnerability reported against a web server that is actually a false positive due to outdated plugin data. What is the best course of action for the tester?

Hard
68

A tester wants to identify the technologies used by a web application before conducting a deeper assessment. Which tool would be most appropriate for passive technology fingerprinting?

Medium
69

During a penetration test, the tester wants to discover publicly exposed IoT devices related to the target organization. Which OSINT tool is specifically designed for searching devices connected to the internet?

Medium
70

A penetration tester is performing active reconnaissance on a web application and needs to discover parameters that the application accepts. Which TWO tools are most commonly used for parameter discovery? (Select TWO.)

Hard
71

During a web application penetration test, the tester wants to discover hidden parameters that the application accepts. Which THREE tools are BEST suited for parameter bruteforcing? (Select THREE.)

Hard
72

During a web application penetration test, the tester wants to discover hidden directories and files on the target web server. Which tool is best suited for this task, and what technique does it use?

Medium
73

A penetration tester is using OpenVAS to perform an authenticated vulnerability scan of a Linux server. The tester has provided valid SSH credentials. Which of the following is a primary benefit of performing an authenticated scan over an unauthenticated scan?

Hard
74

During a penetration test, a tester wants to discover all live hosts on a subnet without performing a full port scan. Which Nmap command is most appropriate for this purpose?

Medium
75

After gaining initial access to an internal network, a penetration tester wants to identify live hosts on a subnet without generating excessive traffic. Which Nmap command would be most appropriate for host discovery using ICMP echo requests and TCP SYN to port 80?

Medium
76

A penetration tester is performing reconnaissance on a target network and wants to identify all live hosts without sending many packets. Which TWO techniques are MOST effective for host discovery in a local subnet? (Select TWO.)

Medium
77

A penetration tester is performing passive reconnaissance on a target organization. Which of the following tools is best suited for gathering information from public sources such as search engines, social media, and website scraping?

Easy
78

A penetration tester is conducting a vulnerability assessment and wants to minimize false positives. Which THREE actions should the tester take? (Select THREE.)

Hard
79

A penetration tester is conducting active reconnaissance on a target network and wants to perform a SYN scan to identify open ports without completing the full TCP handshake. Which Nmap flag should the tester use?

Medium
80

A penetration tester is performing initial reconnaissance on a target domain. Which THREE sources can provide historical data about the target? (Select THREE.)

Medium
81

Which of the following is a common community string used in SNMP enumeration?

Easy
82

A penetration tester is performing passive reconnaissance and wants to identify subdomains associated with a target domain without directly querying the target's DNS servers. Which tool is specifically designed for this purpose?

Easy
83

During a web application penetration test, the tester wants to identify the technologies used by the target website. Which of the following tools is best suited for technology fingerprinting?

Medium
84

A penetration tester is performing service enumeration on a discovered host and wants to grab banners from open ports to identify the exact software and version running. Which of the following command-line tools would be most appropriate for this task?

Medium
85

A penetration tester is performing web application reconnaissance and wants to discover API endpoints and hidden parameters that may not be linked from the main application. Which technique would be most effective for this purpose?

Hard
86

A penetration tester runs a SYN scan against a target and receives SYN-ACK responses from several ports. The tester then runs version detection on those ports. What is the primary purpose of version detection?

Medium
87

A penetration tester is performing passive reconnaissance and wants to find historical versions of the target website, including old pages that may contain sensitive information. Which resource should the tester use?

Medium
88

A penetration tester is assessing a web application and wants to discover hidden directories, files, and parameters. Which THREE of the following tools are most appropriate for this task?

Hard
89

A penetration tester is performing reconnaissance on a target web application. The tester wants to identify the web server software and version without causing any disruption. Which tool is specifically designed for this purpose and can also enumerate other web technologies?

Easy
90

A penetration tester wants to use Google dorking to find publicly accessible documents containing sensitive information on a target domain 'example.com'. Which Google dork would be MOST appropriate to locate PDF files with the word 'confidential'?

Easy
91

A penetration tester is conducting a vulnerability scan of a Linux server using OpenVAS. Which TWO scan configurations would provide the MOST comprehensive results? (Select TWO.)

Medium
92

When performing vulnerability scanning, which of the following best describes a false positive?

Easy
93

A penetration tester is conducting passive reconnaissance using OSINT techniques. Which TWO of the following are examples of passive OSINT sources?

Medium
94

A penetration tester is performing active reconnaissance on a web application and wants to discover hidden API endpoints. Which TWO tools are BEST suited for this task? (Select TWO.)

Medium
95

You are tasked with identifying the technologies used by a web application (e.g., web server, frameworks, libraries) during the reconnaissance phase. Which tool would you use?

Medium
96

A penetration tester is preparing to perform an authenticated vulnerability scan of a network. Which THREE of the following are important considerations before starting the scan? (Select THREE.)

Medium
97

While performing web application reconnaissance, a tester wants to enumerate hidden directories and files on a web server. Which of the following tools is specifically designed for directory brute-forcing?

Medium
98

A penetration tester is evaluating the security of a WordPress site. Which tool is specifically designed to scan WordPress installations for vulnerabilities?

Medium
99

In the context of OSINT, which resource would you use to find historical versions of a company's website that may reveal outdated information or hidden directories?

Easy

Frequently asked questions

What does the Reconnaissance and Enumeration domain cover on the PT0-003 exam?
Be able to classify a technique as passive or active, choose the right tool for OSINT versus DNS versus web enumeration, and write correct Nmap syntax. The key skill is knowing whether your action sends traffic to the target, since that decides the technique and tool.
How many questions are in this domain?
This page lists all 99 Reconnaissance and Enumeration questions in the PT0-003 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Reconnaissance and Enumeration questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
pentest-plus PENTEST-PLUS ptp recon scanning Practice Questions