Courseiva
easyMultiple Choice

PT0-002 Practice Question: Passive DNS reconnaissance uses public resolvers.

During the reconnaissance phase, a penetration tester wants to map out the target's DNS infrastructure without directly interacting with the target's servers. Which of the following techniques BEST achieves this?

⚠ Common exam trap

Watch out — candidates often confuse 'passive reconnaissance' with 'active reconnaissance' and choose a technique like DNS zone transfer or Nmap scanning, which are clearly active and detectable, because they assume any DNS enumeration must involve direct queries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Querying publicly available DNS records

Querying publicly available DNS records (e.g., via passive DNS, WHOIS, or DNS dumpster) allows the tester to gather DNS information without any direct interaction with the target's servers. This technique relies on third-party databases and cached records, avoiding any packets sent to the target, which is essential for stealth during reconnaissance. It aligns with passive information gathering, as defined in the PT0-002 objectives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Performing a DNS zone transfer

    Why it's wrong here

    A DNS zone transfer (AXFR) is an explicit request sent to the target's authoritative name server asking it to replicate its entire zone database. This is an invasive, active enumeration technique because it directly queries the target's infrastructure, and modern DNS servers typically restrict AXFR to authorized secondary servers. Even if the transfer fails, the attempt itself is logged and may alert defenders, so it is not a passive reconnaissance method.

  • ✓

    Querying publicly available DNS records

    Why this is correct

    This technique leverages public DNS resolvers (e.g., 8.8.8.8) or historical DNS databases to retrieve records that are already published in the global namespace, such as A, MX, CNAME, TXT, and NS records. Because the pen tester never sends packets to the target's own servers, the activity is invisible to the target's monitoring tools and falls squarely within passive reconnaissance. This method respects the authorized scope while still revealing infrastructure details, subdomains, and mail server configurations.

  • ✗

    Using Nmap to scan for DNS servers

    Why it's wrong here

    Nmap scanning is inherently active—it sends crafted packets (e.g., TCP SYN, UDP datagrams) to target IP addresses to detect open ports like 53. When a penetration tester uses Nmap to discover DNS servers, they are directly interacting with the target network's hosts, which can trigger intrusion detection systems and firewall logs. This is a distinctly active phase of reconnaissance, not passive information gathering, and it often requires careful rate limiting to avoid detection.

  • ✗

    Sending crafted DNS queries to the target's DNS server

    Why it's wrong here

    Sending crafted DNS queries—whether for version binding, wildcard detection, or brute-forcing subdomains—requires the penetration tester to deliver packets straight to the target's authoritative name server. This creates a direct, loggable interaction with the target's infrastructure, making it an active enumeration method rather than passive reconnaissance. Unlike queries to public resolvers, these packets reach the target's own IP address, so the target can see the source IP, query type, and timing.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.