Courseiva
easyMultiple Choice

PT0-002 Practice Question: During the reconnaissance phase, a penetration…

During the reconnaissance phase, a penetration tester wants to identify subdomains of a target domain without making direct requests to the target's own DNS servers. Which technique would be BEST for this purpose?

⚠ Common exam trap

CompTIA often tests the distinction between active and passive reconnaissance, and the trap here is that candidates may choose zone transfer (Option B) because it is a well-known DNS enumeration technique, but they overlook that it requires direct contact with the target's DNS server and is typically blocked, whereas certificate transparency logs provide a passive alternative that avoids direct interaction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using search engines and public certificate transparency logs

Search engines (e.g., Google dorking) and public certificate transparency logs (e.g., crt.sh) allow a tester to discover subdomains by querying aggregated historical DNS and TLS certificate data, without sending any queries to the target's authoritative DNS servers. This passive reconnaissance technique avoids alerting the target's infrastructure and complies with the requirement of no direct requests to the target's DNS servers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Using the 'nslookup' command interactively

    Why it's wrong here

    Interactive nslookup sends direct DNS queries over the network to resolve records, typically to the target's authoritative or internal DNS servers. Each query is active because it traverses the target's infrastructure and can be recorded in query logs, potentially alerting the security team. It is not passive since the target can observe and react to these requests.

  • ✗

    Performing a zone transfer

    Why it's wrong here

    A zone transfer (AXFR) is an overt, active DNS operation that attempts to copy the entire zone file over a TCP connection. Most servers restrict it with allow-transfer directives, so the request often fails, but the attempt itself is still a direct interaction detectable via DNS logging. Because it actively engages the target's DNS infrastructure, it is explicitly a reconnaissance technique that is not passive.

  • ✓

    Using search engines and public certificate transparency logs

    Why this is correct

    Search engines and public certificate transparency logs are external, third-party aggregators that collect data from the target without any interaction from the tester. CT logs, like crt.sh, are append-only ledgers of issued TLS certificates, compelling certificate authorities to publish them; querying these logs reveals subdomains and other infrastructure. Since this method sends no packets to the target's servers and generates no target-side logs, it is a textbook passive reconnaissance technique.

  • ✗

    Using the 'host' command

    Why it's wrong here

    The host command is a non-interactive DNS utility that sends a standard query, usually to the system's configured resolver or a user-specified DNS server, and prints the answer. Any DNS lookup, regardless of tool, generates network traffic and may be logged by the queried server; if that server is the target's, it is directly active. Unlike examining cached or third-party data, the host command deliberately initiates a resolution transaction that the target can detect.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.