Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

You are conducting a penetration test and need to identify subdomains of a target domain using a passive approach that does not generate traffic to the target's servers. Which technique should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Certificate transparency logs

Certificate transparency logs (e.g., crt.sh) are public logs of SSL/TLS certificates, often containing subdomain names. Querying them is passive and does not interact with the target.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Certificate transparency logs

    Why this is correct

    Certificate transparency logs are a passive discovery resource because they are publicly available, append-only ledgers maintained by independent log operators, and querying them does not involve sending any packets to the target organization's own servers or infrastructure. Services like crt.sh or Censys provide APIs that return certificates issued for a domain, often revealing subdomains, wildcard entries, and even expired certificates that were previously in use. This method leaves no trace on the target's DNS logs, web servers, or intrusion detection systems, making it a classic OSINT/ passive-recon technique. For a penetration tester, it provides a high-yield, low-risk baseline for expanding the attack surface before active testing begins.

  • ✗

    DNS cache snooping

    Why it's wrong here

    DNS cache snooping is an active technique because it sends crafted queries to a recursive resolver, such as an ISP's DNS server, and examines whether the response is marked authoritative or non-authoritative to infer if that resolver has previously cached a specific domain. This interaction generates network traffic and can be detected by the resolver's operators, making it observable and active. It is not passive reconnaissance because it queries third-party infrastructure rather than relying on publicly available, append-only data sources. Since the goal is to remain undetected, this method is inappropriate as a purely passive approach.

  • ✗

    Subdomain bruteforce with gobuster

    Why it's wrong here

    Subdomain brute-force enumeration with gobuster is an active reconnaissance method because it floods a target's authoritative DNS server (or configured resolver) with a large volume of automated DNS queries for common subdomain labels, such as admin, dev, or mail. Each query is a direct, protocol-level interaction with the target's DNS infrastructure, and the volume and pattern of queries can be easily logged by the server, triggering rate limits or security alerts. Unlike querying public transparency logs, this approach relies on direct interrogation and trial-and-error, so it is neither passive nor stealthy. In a PenTest engagement, such activity should be timed and scoped carefully to avoid denial-of-service or detection.

  • ✗

    DNS zone transfer

    Why it's wrong here

    A DNS zone transfer (AXFR/IXFR) is an unequivocally active technique because it queries the target's authoritative name server directly to request a complete copy of the zone file, thereby exposing all DNS records, including hosts, aliases, and infrastructure details. This request is a distinct, loggable interaction that requires specific transport (TCP) and can only succeed if the server is misconfigured to allow transfers to arbitrary hosts, which is rare in hardened environments. Even when unsuccessful, the query itself is visible to the target and may be flagged as an information-gathering attempt. Because it relies on direct server interaction, it is not passive and should only be performed with explicit authorization.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.