Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

You are conducting passive reconnaissance on a target organization. Which of the following are examples of passive reconnaissance techniques? (Select TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Querying certificate transparency logs

Passive reconnaissance involves collecting information without directly interacting with the target's systems. WHOIS lookups and certificate transparency logs are passive. DNS zone transfer and port scanning are active. Social engineering is active.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Querying certificate transparency logs

    Why this is correct

    Querying certificate transparency logs is passive because these logs are publicly auditable ledgers of all issued TLS/SSL certificates, maintained by independent log operators like Google and Cloudflare. An attacker can query them via services such as crt.sh or the ct.googleapis.com API to discover subdomains and certificate details without ever sending a packet to the target's own infrastructure, thereby leaving no trace in the target's logs.

  • ✗

    DNS zone transfer

    Why it's wrong here

    DNS zone transfer is an active reconnaissance technique because it involves sending an AXFR query directly to the target's authoritative DNS server, requesting a full copy of the zone file. This requires interacting with the target's infrastructure and typically only succeeds if the server is misconfigured to allow transfers from any host; a properly configured server will refuse, and the request itself is recorded in the DNS server's logs.

  • ✗

    Scanning ports with Nmap

    Why it's wrong here

    Scanning ports with Nmap is inherently active as it transmits crafted packets—TCP SYN scans, UDP probes, ICMP pings—to the target host. Every probe elicits a response (or a timeout-driven inferred state) that the scanner observes, and these packets are logged by intrusion detection systems and firewalls, making the activity detectable and attributable to the attacker's source IP.

  • ✗

    Sending phishing emails

    Why it's wrong here

    Sending phishing emails is clearly active because it involves direct interaction with the target's users and systems, delivering a malicious payload or credential-harvesting link to a recipient. This creates network traffic to and from the target, triggers email gateway logging, and often requires subsequent user interaction—making it a high-risk, intrusive technique that is the antithesis of passive reconnaissance.

  • ✓

    Performing a WHOIS lookup

    Why this is correct

    Performing a WHOIS lookup is passive because it queries a public registration database operated by regional internet registries (RIRs) and domain registrars, such as ARIN or Verisign, rather than the target's own servers. This yields registrar, nameserver, and administrative contact information from cached third-party data, and the query is sent to the WHOIS server, not the target, so the target is unaware of the inquiry.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.