PT0-002 Reconnaissance and Enumeration Practice Question
During the information gathering phase, a penetration tester wants to discover subdomains of a target domain using DNS queries and potentially brute-forcing common subdomain names. Which of the following tools is specifically designed for subdomain enumeration and can perform both passive and active techniques?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amass
Amass is a tool that performs subdomain enumeration using passive sources and active brute-forcing. Gobuster and dirsearch are for directory/file enumeration. Nmap is for port scanning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Nmap
Why it's wrong here
Nmap is fundamentally a network mapping and port scanning utility that sends crafted packets to hosts to discover open ports, services, and OS fingerprints. While it includes a dns-brute NSE script for brute-forcing hostnames, that is a secondary add-on and lacks the breadth of passive intelligence sources—such as certificate transparency logs, search engine scraping, or DNS archive queries—that subdomain enumeration tools aggregate. In a real engagement, relying on Nmap for subdomain discovery would yield a sparse host list and likely miss the less common, security-relevant subdomains a tester needs.
- ✗
dirsearch
Why it's wrong here
dirsearch is a web content discovery tool that sends HTTP requests to a single target web root, cycling through a wordlist of paths and files to identify existing resources by analyzing response codes (e.g., 200, 301, 403). It operates entirely at the URI level after a hostname or IP is already known, so it has no mechanism to query DNS, parse certificate transparency records, or connect to passive OSINT APIs. By its design, dirsearch answers 'what directories exist on this web server?' not 'what hostnames point to this organization?'—the latter being the core task in subdomain enumeration.
- ✗
Gobuster
Why it's wrong here
Gobuster is a versatile brute-force tool with multiple modes, and its DNS mode does send DNS queries to a configured resolver for every word in a given wordlist to test if it resolves as a subdomain. However, this active brute-force approach only finds names that exist in the tester's wordlist and that pass DNS resolution; it ignores passive sources like certificate transparency logs, reverse WHOIS, or web search results that can reveal subdomains not guessable through a list. Amass, by contrast, integrates dozens of passive data feeds and cross-correlates findings using graph analysis, giving far greater coverage and reducing the chance of missing non-standard subdomains that a brute-force dictionary would overlook.
- ✓
Amass
Why this is correct
Amass is a dedicated open-source subdomain enumeration and attack surface mapping tool developed under the OWASP umbrella. It aggregates passive data from a wide range of public sources—including certificate transparency logs (e.g., crt.sh), DNS archives, search engines, and security APIs like VirusTotal, Shodan, and AlienVault—then supplements that with active techniques such as DNS brute-forcing, zone transfer attempts, and recursive resolution to validate each discovered name. Its graph-based correlation engine links subdomains to related domains and IPs, uncovering infrastructure that a simple brute-forcer or directory scanner would never reveal. This makes Amass not just a subdomain finder, but a foundational tool for building a complete target asset inventory during the information gathering phase.
Go deeper
Related to this question
Learn chapter
BloodHound and Active Directory Enumeration
Key term
Port scanning
Port scanning is the process of probing a computer or network device to discover which network ports are open, closed, or filtered, revealing potential entry points for services and applications.
Key term
Nmap
Nmap is a network scanning tool used to discover hosts, services, and operating systems on a computer network.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.