PT0-002 Reconnaissance and Enumeration Practice Question
During a penetration test, the tester runs a DNS zone transfer attempt against a target domain. The zone transfer fails. What is the most likely reason?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The DNS server is configured to deny zone transfers from unauthorized hosts
DNS zone transfers are typically restricted by default to authorized secondary DNS servers only. Misconfigured DNS servers might allow zone transfers from any host, but it's uncommon. The failure is likely due to security restrictions. The authoritative server is not necessarily offline, and the domain might not exist otherwise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The DNS server is configured to deny zone transfers from unauthorized hosts
Why this is correct
Zone transfers use the AXFR query type to replicate an entire DNS zone. The server's allow-transfer ACL determines which IP addresses may request a full zone copy; when the tester's source IP is not in that list, the server typically responds with a REFUSED or 'Transfer failed' error while still answering normal recursive/authoritative queries, so the attempt appears blocked.
- ✗
The DNS server is offline
Why it's wrong here
If the DNS server were truly offline, the tester would receive no response at all to any DNS query—including simple A/AAAA record lookups—because the server would not be listening on UDP/TCP port 53. In this scenario, the zone transfer attempt is rejected with an explicit DNS error, proving that the server is reachable and processing the query; therefore, 'offline' cannot be the cause.
- ✗
The tester used the wrong tool
Why it's wrong here
The AXFR query is a standard DNS protocol operation, not something that requires a specialized or unique tool. Tools like dig, host, nslookup, and dnsrecon all issue the same wire-format request; if the server allowed the transfer, any of them would retrieve the zone data. Using a different tool would not change the server's access-control decision.
- ✗
The domain does not exist
Why it's wrong here
A nonexistent domain would cause the DNS server to return an NXDOMAIN response for any query type, including AXFR, because the server has no authoritative zone for it. However, the question specifically describes a zone transfer failure; if the domain didn't exist, the tester also wouldn't be able to resolve the nameserver or perform other queries against it. Since those other operations succeed, the domain must exist and the failure is due to the transfer restriction.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.