Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

During a penetration test, the tester wants to gather information about the target organization's domain registration and contact details without sending any traffic to the target. Which OSINT source should the tester use first?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WHOIS

WHOIS lookups provide registration details for domains, including administrative contacts, name servers, and expiration dates, without sending traffic to the target. Shodan searches for internet-connected devices, Censys provides certificates and host information, and crt.sh shows certificate transparency logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Shodan

    Why it's wrong here

    Shodan is an internet-wide search engine that continuously scans IPv4/IPv6 address space and indexes the banners, service fingerprints, and open ports reported by internet-connected devices, including IoT and ICS systems. Although it can reveal a target's exposed services or accidentally indexed web headers, it does not perform registrar WHOIS lookups and has no authoritative domain registration database. Thus, Shodan cannot provide registrant contact, creation date, or nameserver details for a domain registration, making it a wrong choice for this task.

  • ✗

    crt.sh

    Why it's wrong here

    crt.sh is a community web front-end for certificate transparency (CT) logs, enabling anyone to query every publicly logged TLS/SSL certificate issued for a domain and view its subject alternative names, issuance/expiration dates, and issuer. The resulting data can help an attacker enumerate subdomains or discover shadow IT, but CT logs never contain registrant info, registrar name, or domain status codes. Because the requirement is specifically about gathering domain registration details, crt.sh is not the correct passive source.

  • ✓

    WHOIS

    Why this is correct

    WHOIS is a standard query/response protocol, usually over TCP port 43, that retrieves the authoritative registration record for a domain from the registry and registrar databases, including registrant and administrative contacts, creation/expiration timestamps, nameservers, and registrar identity. For a penetration tester, performing a passive WHOIS lookup during the information-gathering phase is the direct way to obtain domain registration details and can yield nameservers for later DNS enumeration or contact references for social engineering. Therefore, WHOIS is the correct answer because it specifically returns the registration information requested.

  • ✗

    Censys

    Why it's wrong here

    Censys is a research platform that continuously performs internet-wide ZMap-style scans and stores detailed observations about hosts, including open ports, tls/ssl certificate chains, http responses, and other service metadata, all searchable through its query engine. It supplies certificate transparency subdomains and historical host data, but it is not a registration authority and does not maintain WHOIS records beyond possibly echoing registration data in SSL certificate extensions. As a result, Censys cannot be used to gather domain registration details such as registrant or registrar information, making it a wrong choice here.

Go deeper

Related to this question

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.