PT0-002 Reconnaissance and Enumeration Practice Question
During a penetration test, the tester wants to discover publicly exposed IoT devices related to the target organization. Which OSINT tool is specifically designed for searching devices connected to the internet?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Shodan
Shodan is a search engine that indexes banners from internet-connected devices, including IoT, webcams, routers, and industrial control systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Censys
Why it's wrong here
Censys also performs large-scale internet-wide scanning and can find exposed services and devices, but it is more of an alternative rather than the canonical tool for IoT/device discovery. While Censys indexes SSL certificates and service banners, Shodan is far more widely recognized and specifically associated with discovering internet-connected devices such as cameras, routers, and industrial control systems. For a typical penetration test, Shodan would be the primary go-to, making Censys a plausible but less precise answer.
- ✓
Shodan
Why this is correct
Shodan is the correct answer because it is a dedicated search engine for internet-connected devices. It works by scanning the entire IPv4 (and IPv6) address space and indexing the banners returned by services like HTTP, SSH, FTP, and Telnet. Penetration testers use Shodan to quickly identify public-facing devices, exposed industrial control systems, and services running on unusual ports, making it the industry-standard tool for internet-facing device discovery.
- ✗
Maltego
Why it's wrong here
Maltego is a graphical OSINT and data-mining tool that focuses on mapping relationships between entities such as people, domains, email addresses, and network infrastructure. It does not directly scan or search for internet-connected devices; instead, it aggregates data from other sources and visualizes connections. While Maltego can help in reconnaissance, it is not a device search engine and would not be the appropriate tool for discovering exposed/Internet-facing devices.
- ✗
theHarvester
Why it's wrong here
theHarvester is a passive reconnaissance tool designed to gather emails, subdomains, hosts, and virtual hosts from public sources like search engines, Google, Bing, and PGP key servers. It does not perform device discovery or banner grabbing, and its output is oriented toward building a target list of names and email addresses rather than identifying internet-connected devices. Therefore, it fails the specific requirement of discovering public-facing devices.
Go deeper
Related to this question
Learn chapter
Penetration Testing Tools
Key term
OSINT
OSINT (Open Source Intelligence) is the practice of collecting and analyzing publicly available information from free or commercially available sources to support intelligence gathering, cybersecurity assessments, and penetration testing.
Key term
Shodan
Shodan is a search engine that lets you find specific types of internet-connected devices, such as webcams, routers, and servers, by scanning the internet and indexing their services and banners.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.