PT0-002 Reconnaissance and Enumeration Practice Question
During a penetration test, the tester wants to gather information about the target organization's domain registration and contact details without sending any traffic to the target. Which OSINT source should the tester use first?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WHOIS
WHOIS lookups provide registration details for domains, including administrative contacts, name servers, and expiration dates, without sending traffic to the target. Shodan searches for internet-connected devices, Censys provides certificates and host information, and crt.sh shows certificate transparency logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Shodan
Why it's wrong here
Shodan is an internet-wide search engine that continuously scans IPv4/IPv6 address space and indexes the banners, service fingerprints, and open ports reported by internet-connected devices, including IoT and ICS systems. Although it can reveal a target's exposed services or accidentally indexed web headers, it does not perform registrar WHOIS lookups and has no authoritative domain registration database. Thus, Shodan cannot provide registrant contact, creation date, or nameserver details for a domain registration, making it a wrong choice for this task.
- ✗
crt.sh
Why it's wrong here
crt.sh is a community web front-end for certificate transparency (CT) logs, enabling anyone to query every publicly logged TLS/SSL certificate issued for a domain and view its subject alternative names, issuance/expiration dates, and issuer. The resulting data can help an attacker enumerate subdomains or discover shadow IT, but CT logs never contain registrant info, registrar name, or domain status codes. Because the requirement is specifically about gathering domain registration details, crt.sh is not the correct passive source.
- ✓
WHOIS
Why this is correct
WHOIS is a standard query/response protocol, usually over TCP port 43, that retrieves the authoritative registration record for a domain from the registry and registrar databases, including registrant and administrative contacts, creation/expiration timestamps, nameservers, and registrar identity. For a penetration tester, performing a passive WHOIS lookup during the information-gathering phase is the direct way to obtain domain registration details and can yield nameservers for later DNS enumeration or contact references for social engineering. Therefore, WHOIS is the correct answer because it specifically returns the registration information requested.
- ✗
Censys
Why it's wrong here
Censys is a research platform that continuously performs internet-wide ZMap-style scans and stores detailed observations about hosts, including open ports, tls/ssl certificate chains, http responses, and other service metadata, all searchable through its query engine. It supplies certificate transparency subdomains and historical host data, but it is not a registration authority and does not maintain WHOIS records beyond possibly echoing registration data in SSL certificate extensions. As a result, Censys cannot be used to gather domain registration details such as registrant or registrar information, making it a wrong choice here.
Go deeper
Related to this question
Learn chapter
PowerShell for Penetration Testing
Key term
OSINT
OSINT (Open Source Intelligence) is the practice of collecting and analyzing publicly available information from free or commercially available sources to support intelligence gathering, cybersecurity assessments, and penetration testing.
Key term
Shodan
Shodan is a search engine that lets you find specific types of internet-connected devices, such as webcams, routers, and servers, by scanning the internet and indexing their services and banners.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.