Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

During a penetration test, you need to gather information about a target's email addresses and employee names without directly interacting with the target's systems. Which tool is most appropriate for this passive reconnaissance task?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

theHarvester

theHarvester is an OSINT tool designed to gather emails, subdomains, IPs, and employee names from public sources like search engines and social media. Maltego is more for relationship mapping, Shodan for internet-facing devices, and Censys for certificate and network data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Shodan

    Why it's wrong here

    Shodan is incorrect because it is a search engine for internet-connected devices, not email addresses. It indexes service banners, open ports, and device fingerprints across the global IP space, making it invaluable for discovering exposed infrastructure and industrial control systems, but it does not crawl mailboxes or extract email addresses from public sources. During a pentest, Shodan helps map an organization's external attack surface, yet it is fundamentally not designed for email harvesting.

  • ✗

    Censys

    Why it's wrong here

    Censys is incorrect because it performs continuous Internet-wide scans of IP addresses, open ports, and TLS certificates, rather than collecting email data. Its strength lies in asset discovery, vulnerability identification, and analyzing certificate transparency logs, all of which support infrastructure reconnaissance but not the enumeration of emails. While Censys can provide insights into an organization's exposed services, it cannot fulfill the specific requirement of gathering email addresses during a penetration test.

  • ✗

    Maltego

    Why it's wrong here

    Maltego is incorrect for this task because, although it can be used for link analysis and OSINT correlation, it is not specifically focused on email harvesting out of the box. Maltego is a graphical intelligence platform that visualizes relationships between entities, and while it has transforms that can query email-related sources, using it requires configuring those transforms and integrating third-party data; it is not a dedicated email collector like theHarvester, and its primary value is in connecting and analyzing data rather than directly extracting email addresses.

  • ✓

    theHarvester

    Why this is correct

    theHarvester is the correct answer because it is a dedicated OSINT tool engineered to passively gather emails, subdomains, hostnames, and employee names from public sources. It queries search engines like Bing and Google, PGP key servers, and other open data repositories, making it ideal for the early reconnaissance phase of a penetration test. Its specific focus on email harvesting and subdomain enumeration aligns precisely with the task of gathering information about an organization's digital footprint, unlike general-purpose scanners or link-analysis platforms.

Go deeper

Related to this question

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.