Courseiva

PT0-003 · topic practice

Reconnaissance and Enumeration practice questions

Reconnaissance and Enumeration covers passive and active information gathering before exploitation: OSINT, DNS and subdomain discovery, host discovery, service and version detection, and web content discovery. Questions present a scenario and ask you to pick the correct technique, tool, or command, or to distinguish passive methods from those that touch the target's infrastructure.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Reconnaissance and Enumeration

What the exam tests

What to know about Reconnaissance and Enumeration

Be able to classify a technique as passive or active, choose the right tool for OSINT versus DNS versus web enumeration, and write correct Nmap syntax. The key skill is knowing whether your action sends traffic to the target, since that decides the technique and tool.

Passive subdomain discovery via certificate transparency logs, DNS aggregators, and search engines without querying target servers

OSINT tooling such as theHarvester, Maltego, and Shodan for employees, emails, and infrastructure

Web content discovery using directory brute-forcing tools like Gobuster, Dirb, and Feroxbuster

Nmap host discovery with -sn to find live hosts without port scanning

Watch out for

Common Reconnaissance and Enumeration exam traps

  • ▸Treating active DNS queries or zone transfers as passive; any query to the target's nameservers generates traffic and is active reconnaissance
  • ▸Confusing host discovery (-sn) with port scanning; -sn only pings and does not enumerate open ports or services
  • ▸Assuming directory brute-forcing is passive; it sends requests to the target web server and is noisy, detectable active enumeration

Practice set

Reconnaissance and Enumeration questions

20 questions · select your answer, then reveal the explanation

During a penetration test, you need to enumerate SNMP information from network devices. Which of the following tools or commands can be used for SNMP enumeration? (Select TWO.)

Question 2mediummultiple choice
Read the full DNS explanation →

During a penetration test, the tester wants to gather information about a target using publicly available DNS records, including mail servers, name servers, and possibly TXT records. Which type of DNS query would be most useful for obtaining a comprehensive list of these records?

Question 3hardmultiple choice
Read the full DNS explanation →

A tester is performing DNS enumeration on a domain and wants to attempt a zone transfer. Which DNS record type is primarily used for zone transfers?

A penetration tester is performing passive reconnaissance on a target organization. Which TWO of the following sources can provide information about the organization's historical web content? (Select TWO.)

During a web application penetration test, the tester wants to discover hidden API endpoints. Which THREE of the following techniques can be used to achieve this? (Select THREE.)

A penetration tester is using Google dorks to find sensitive information about a target organization. Which search operator would help the tester find PDF files containing the word 'confidential' on the target's website?

A penetration tester is performing SNMP enumeration on a target network. Which command would likely be used to extract information from a device with the community string 'public'?

A penetration tester is performing active reconnaissance on a target network and wants to use Nmap to identify operating systems and run default scripts against discovered services. Which two Nmap options should the tester include? (Choose TWO.)

During a penetration test, the tester discovers that the target web application uses a content delivery network (CDN) that hides the origin server's IP address. Which technique would BEST help identify the true IP address of the backend server?

Question 10mediummulti select
Read the full DNS explanation →

A penetration tester is tasked with performing a DNS enumeration of a target domain to discover subdomains. Which THREE tools are commonly used for subdomain bruteforcing? (Select THREE.)

A penetration tester is conducting passive reconnaissance against a target organization. Which TWO of the following techniques would be most appropriate for gathering information about the organization's infrastructure and employees without directly interacting with the target's systems?

During an active reconnaissance phase, a penetration tester runs Nmap against a target and obtains the following results: Host is up, ports 22, 80, and 443 are open. The tester then runs a vulnerability scan using Nessus with unauthenticated credentials. Which THREE of the following issues should the tester be most concerned about regarding the accuracy and completeness of the Nessus scan results?

A penetration tester is performing web application reconnaissance. The tester wants to discover hidden directories and files, identify the technologies used, and find API endpoints. Which THREE of the following tools are best suited for these tasks?

During an external penetration test, a tester discovers that the target organization has a Microsoft Exchange server exposed to the internet. The tester wants to enumerate valid user accounts without triggering account lockout policies or generating excessive authentication failures. Which tool and technique should the tester use?

A penetration tester is conducting reconnaissance on a target organization's external infrastructure. The tester wants to identify subdomains that may not be publicly advertised. Which two techniques are most effective for discovering subdomains during passive reconnaissance? (Choose two.)

A penetration tester is conducting reconnaissance on a target organization's external footprint. The tester discovers a list of IP addresses and wants to determine which ones belong to the target and what services they expose, while minimizing the chance of triggering intrusion detection systems. Which approach best balances thoroughness and stealth?

A penetration tester is performing OSINT reconnaissance against a target company and wants to gather information that could support later social engineering and technical attacks. Which two sources are most likely to reveal employee names, email addresses, and technology stack details without directly contacting the target's infrastructure? (Choose two.)

During a penetration test, you need to gather information about a target's email addresses and employee names without directly interacting with the target's systems. Which tool is most appropriate for this passive reconnaissance task?

You are performing a vulnerability scan on a web application and notice that the scanner reports a high-severity SQL injection vulnerability. However, manual testing confirms that the input is properly sanitized. Which term best describes this situation?

Which Nmap scan type sends SYN packets to determine open ports without completing the TCP three-way handshake?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Reconnaissance and Enumeration sessions

Start a Reconnaissance and Enumeration only practice session

Every question in these sessions is drawn from the Reconnaissance and Enumeration domain — nothing else.

Related practice questions

Related PT0-003 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PT0-003 exam test about Reconnaissance and Enumeration?
Be able to classify a technique as passive or active, choose the right tool for OSINT versus DNS versus web enumeration, and write correct Nmap syntax. The key skill is knowing whether your action sends traffic to the target, since that decides the technique and tool.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Reconnaissance and Enumeration questions in a focused session?
Yes — the session launcher on this page draws every question from the Reconnaissance and Enumeration domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PT0-003 topics?
Use the topic links above to move to related areas, or go back to the PT0-003 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PT0-003 exam covers. They are not copied from any real exam or dump site.