PT0-002 Reconnaissance and Enumeration Practice Question
In the context of OSINT, which resource would you use to find historical versions of a company's website that may reveal outdated information or hidden directories?
⚠ Common exam trap
Candidates often confuse OSINT tools focused on current infrastructure (Shodan, Censys) or certificate data (crt.sh) with the only tool that provides historical web content snapshots, the Wayback Machine.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Wayback Machine
The Wayback Machine (archive.org) is the correct resource because it archives historical snapshots of websites, allowing you to view past versions that may contain outdated information, hidden directories, or old configurations no longer present on the live site. This is a core OSINT technique for discovering legacy content or forgotten endpoints.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
crt.sh
Why it's wrong here
crt.sh provides a searchable interface to Certificate Transparency (CT) logs, allowing analysts to identify SSL/TLS certificates issued for a domain and thereby enumerate subdomains. However, it only contains certificate metadata such as issuer, validity period, and subject alternative names, not the actual content of the websites that used those certificates. Therefore, it cannot be used to retrieve archived or historical versions of web pages, which is the specific requirement in this scenario.
- ✗
Censys
Why it's wrong here
Censys is a search engine that continuously scans the entire IPv4 and IPv6 address space, recording detailed information about services, open ports, and TLS certificates. While it does store historical network-level data, its records are structured around hosts and protocols rather than the rendered content of web pages. Consequently, Censys cannot provide the archived snapshots of a site's HTML and visual layout that the Wayback Machine offers.
- ✗
Shodan
Why it's wrong here
Shodan indexes internet-connected devices by probing ports and services, collecting response banners and metadata such as server software and location. Although Shodan occasionally captures screenshots of web services, these are incidental to its scanning and are not a comprehensive historical archive of a site's content. Therefore, it falls far short of the Wayback Machine's ability to view how a URL appeared at any given point in the past.
- ✓
Wayback Machine
Why this is correct
The Wayback Machine is an archival service operated by the Internet Archive that crawls the web and stores full snapshots of websites over time, including HTML, CSS, JavaScript, and images. It allows OSINT researchers to query a URL and retrieve the exact version of a page as it appeared on a chosen date, making it the definitive resource for historical website content. Unlike certificate or network-focused search engines, it preserves the actual user-facing content rather than infrastructure metadata.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.