easyMultiple Choice
PT0-002 Practice Question: During the reconnaissance phase, a penetration…
During the reconnaissance phase, a penetration tester wants to identify subdomains of a target domain without making direct requests to the target's own DNS servers. Which technique would be BEST for this purpose?
⚠ Common exam trap
CompTIA often tests the distinction between active and passive reconnaissance, and the trap here is that candidates may choose zone transfer (Option B) because it is a well-known DNS enumeration technique, but they overlook that it requires direct contact with the target's DNS server and is typically blocked, whereas certificate transparency logs provide a passive alternative that avoids direct interaction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using search engines and public certificate transparency logs
Search engines (e.g., Google dorking) and public certificate transparency logs (e.g., crt.sh) allow a tester to discover subdomains by querying aggregated historical DNS and TLS certificate data, without sending any queries to the target's authoritative DNS servers. This passive reconnaissance technique avoids alerting the target's infrastructure and complies with the requirement of no direct requests to the target's DNS servers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using the 'nslookup' command interactively
Why it's wrong here
Interactive nslookup sends direct DNS queries over the network to resolve records, typically to the target's authoritative or internal DNS servers. Each query is active because it traverses the target's infrastructure and can be recorded in query logs, potentially alerting the security team. It is not passive since the target can observe and react to these requests.
- ✗
Performing a zone transfer
Why it's wrong here
A zone transfer (AXFR) is an overt, active DNS operation that attempts to copy the entire zone file over a TCP connection. Most servers restrict it with allow-transfer directives, so the request often fails, but the attempt itself is still a direct interaction detectable via DNS logging. Because it actively engages the target's DNS infrastructure, it is explicitly a reconnaissance technique that is not passive.
- ✓
Using search engines and public certificate transparency logs
Why this is correct
Search engines and public certificate transparency logs are external, third-party aggregators that collect data from the target without any interaction from the tester. CT logs, like crt.sh, are append-only ledgers of issued TLS certificates, compelling certificate authorities to publish them; querying these logs reveals subdomains and other infrastructure. Since this method sends no packets to the target's servers and generates no target-side logs, it is a textbook passive reconnaissance technique.
- ✗
Using the 'host' command
Why it's wrong here
The host command is a non-interactive DNS utility that sends a standard query, usually to the system's configured resolver or a user-specified DNS server, and prints the answer. Any DNS lookup, regardless of tool, generates network traffic and may be logged by the queried server; if that server is the target's, it is directly active. Unlike examining cached or third-party data, the host command deliberately initiates a resolution transaction that the target can detect.
Visual reference
Go deeper
Related to this question
Learn chapter
OSINT and Passive Reconnaissance
Key term
Passive reconnaissance
Passive reconnaissance is the process of gathering information about a target system or network without directly interacting with it, using publicly available sources and stealthy observation.
Key term
Google dorking
Google dorking is the practice of using advanced search operators in Google to uncover sensitive information that companies or individuals unintentionally expose on the internet.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.