Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

Which of the following tools is most commonly used for passive reconnaissance by querying certificate transparency logs to discover subdomains?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

crt.sh

crt.sh is a certificate transparency log search tool that can be used to find subdomains by querying SSL/TLS certificates issued for a domain.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    crt.sh

    Why this is correct

    crt.sh is a dedicated web service and API that aggregates and searches public Certificate Transparency (CT) logs, making it the most commonly used tool for passively discovering subdomains by querying issued SSL/TLS certificates. Because it queries the CT logs directly, it requires no interaction with the target's infrastructure and returns a comprehensive list of subdomains for free without API keys. This passive approach is a standard first step in reconnaissance during penetration testing and bug bounty engagements.

  • ✗

    Censys

    Why it's wrong here

    Censys is a general-purpose internet scanning and search engine that indexes devices, services, and certificates, but it does not offer the same focused, CT-log-specific search that crt.sh provides. While it can return certificate data and subdomains from its own scans, its main purpose is asset discovery across the entire internet, not passive subdomain enumeration from certificate transparency logs. Additionally, Censys typically requires an API key and its free tier limits query volume, making it a less common go-to for this specific task.

  • ✗

    theHarvester

    Why it's wrong here

    theHarvester is a reconnaissance tool that aggregates email addresses, subdomains, and hostnames by querying public sources such as search engines, PGP key servers, and Shodan, but it does not natively query Certificate Transparency logs. Unlike crt.sh, which focuses specifically on CT certificate data, theHarvester relies on third-party sources that may not have the same TLS certificate coverage, and its subdomain results are a byproduct of broader OSINT collection. It also lacks a direct integration with CT log aggregators, making it less suitable for this specific passive reconnaissance purpose.

  • ✗

    Shodan

    Why it's wrong here

    Shodan is a search engine that scans and indexes internet-connected devices, open ports, and services, rather than being a dedicated Certificate Transparency log search tool. It can expose subdomains indirectly when SSL certificates on port 443 are captured, but this is a secondary byproduct of device and service fingerprinting, not a primary function. Furthermore, Shodan's scanning methodology actively probes the target's infrastructure, which contradicts the passive nature of CT log enumeration that crt.sh provides, making it an unsuitable answer here.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.