PT0-002 Reconnaissance and Enumeration Practice Question
You are conducting passive reconnaissance on a target organization. Which of the following are examples of passive reconnaissance techniques? (Select TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Querying certificate transparency logs
Passive reconnaissance involves collecting information without directly interacting with the target's systems. WHOIS lookups and certificate transparency logs are passive. DNS zone transfer and port scanning are active. Social engineering is active.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Querying certificate transparency logs
Why this is correct
Querying certificate transparency logs is passive because these logs are publicly auditable ledgers of all issued TLS/SSL certificates, maintained by independent log operators like Google and Cloudflare. An attacker can query them via services such as crt.sh or the ct.googleapis.com API to discover subdomains and certificate details without ever sending a packet to the target's own infrastructure, thereby leaving no trace in the target's logs.
- ✗
DNS zone transfer
Why it's wrong here
DNS zone transfer is an active reconnaissance technique because it involves sending an AXFR query directly to the target's authoritative DNS server, requesting a full copy of the zone file. This requires interacting with the target's infrastructure and typically only succeeds if the server is misconfigured to allow transfers from any host; a properly configured server will refuse, and the request itself is recorded in the DNS server's logs.
- ✗
Scanning ports with Nmap
Why it's wrong here
Scanning ports with Nmap is inherently active as it transmits crafted packets—TCP SYN scans, UDP probes, ICMP pings—to the target host. Every probe elicits a response (or a timeout-driven inferred state) that the scanner observes, and these packets are logged by intrusion detection systems and firewalls, making the activity detectable and attributable to the attacker's source IP.
- ✗
Sending phishing emails
Why it's wrong here
Sending phishing emails is clearly active because it involves direct interaction with the target's users and systems, delivering a malicious payload or credential-harvesting link to a recipient. This creates network traffic to and from the target, triggers email gateway logging, and often requires subsequent user interaction—making it a high-risk, intrusive technique that is the antithesis of passive reconnaissance.
- ✓
Performing a WHOIS lookup
Why this is correct
Performing a WHOIS lookup is passive because it queries a public registration database operated by regional internet registries (RIRs) and domain registrars, such as ARIN or Verisign, rather than the target's own servers. This yields registrar, nameserver, and administrative contact information from cached third-party data, and the query is sent to the WHOIS server, not the target, so the target is unaware of the inquiry.
Go deeper
Related to this question
Learn chapter
Lateral Movement Techniques
Key term
Active reconnaissance
Active reconnaissance is the process of directly interacting with a target system or network to gather information, often through scanning and probing.
Key term
Port scanning
Port scanning is the process of probing a computer or network device to discover which network ports are open, closed, or filtered, revealing potential entry points for services and applications.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.