Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

During the information gathering phase, a penetration tester uses Google dorks to find exposed documents on a target's website. Which Google dork would be most appropriate to find PDF files containing sensitive information?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

filetype:pdf

The filetype:pdf dork restricts results to PDF files. Other dorks target different file types or content.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    filetype:pdf

    Why this is correct

    filetype:pdf restricts Google's index to files with the PDF extension, which is ideal for information gathering because PDFs published on a target domain—such as user guides, annual reports, or internal memos—frequently contain metadata, employee names, and technology stack details that are not visible in ordinary HTML pages. During passive reconnaissance, this operator narrows results to a discrete document format that often escapes normal web crawling and may reveal sensitive or forgotten disclosures.

  • ✗

    inurl:admin

    Why it's wrong here

    The inurl:admin operator returns any indexed URL containing the string 'admin' anywhere in its path, such as /admin/login.php or /administrator/, so it is valuable for discovering management consoles but not for general information gathering. Because many legitimate pages include 'admin' in navigation or comments, this search produces numerous false positives and is better suited to vulnerability identification and access-phase targeting than to broad open-source intelligence collection.

  • ✗

    site:target.com password

    Why it's wrong here

    The query site:target.com password asks Google to show every indexed page on that domain that contains the literal word 'password', but the term appears in login forms, password reset pages, help articles, and even source code comments, making the result set extremely noisy. While it can occasionally uncover hardcoded credentials or test files, it is not a targeted file-type filter, so it lacks the precision of filetype:pdf and requires substantial manual review to separate true information disclosures from routine UI text.

  • ✗

    intitle:index.of

    Why it's wrong here

    The intitle:index.of operator uses Google's title search to identify web servers that have directory listing enabled, showing a raw index of files and subdirectories when the server's autoindex feature is on. This can expose sensitive files if the target misconfigured its web server, but many modern servers disable directory browsing by default, and the search is far less reliable and less comprehensive than filtering for a specific document type like PDFs during the information-gathering phase.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.