easyMultiple Choice
PT0-002 Practice Question: Tools is primarily used for enumerating…
Which of the following tools is primarily used for enumerating subdomains via search engine queries?
⚠ Common exam trap
A common mix-up: candidates confuse Nmap's DNS brute-force scripts (like dns-brute) with passive subdomain enumeration, but Nmap actively queries DNS servers, whereas theHarvester passively collects data from search engines without touching the target's infrastructure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
theHarvester
theHarvester is specifically designed to gather emails, subdomains, IPs, and URLs from public sources, including search engines like Google, Bing, and Yahoo. It leverages search engine APIs and scraping techniques to enumerate subdomains without directly interacting with the target infrastructure, making it the correct tool for this task.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Metasploit
Why it's wrong here
Metasploit is a penetration testing framework centered on exploitation and post-exploitation, containing hundreds of modules for delivering payloads and maintaining access. While it includes auxiliary scanners that can perform service or web enumeration, its primary design goal is not passive OSINT subdomain discovery. Using Metasploit for this task would be overkill and indirect, as the enumeration is secondary to its exploit workflow.
- ✗
Netcat
Why it's wrong here
Netcat, often called the Swiss Army knife of networking, is a raw TCP/UDP utility used for banner grabbing, port testing, and relaying connections such as reverse shells. It has no built-in mechanism to query search engines or PGP key servers, so it cannot perform the passive subdomain enumeration theHarvester is purpose-built for. It requires an already known target and simply reads and writes bytes across a socket.
- ✓
theHarvester
Why this is correct
theHarvester is a dedicated OSINT (open-source intelligence) tool that systematically queries search engines, PGP key servers, and Shodan to collect emails, subdomains, hosts, and employee names. Its passive, API-based data collection is explicitly designed for reconnaissance of a domain without actively sending packets to the target. This makes it the correct choice for enumeration tasks that leverage public information.
- ✗
Nmap
Why it's wrong here
Nmap is an active network mapper that sends crafted probes (TCP SYN, ICMP, UDP) to a target host to identify open ports, running services, and operating systems. Although Nmap supports DNS brute-force scripts like dns-brute for subdomain discovery, that requires direct interaction with the target's name servers and is not a passive OSINT approach. Its primary enumeration focus is on network-level fingerprinting, not on harvesting domain metadata from third-party public sources.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.