Reconnaissance and Enumeration PT0-003 Practice Quiz
324 exam-style questions covering 21% of the PT0-003 exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the CompTIA PenTest+ practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
Which description best matches Active reconnaissance in PenTest+ Objective 2.0 Reconnaissance and Enumeration?
- A. Active reconnaissance directly interacts with targets or target-controlled infrastructure to gather information.
- B. Passive reconnaissance gathers information without directly interacting with the target’s systems.
- C. Open-source intelligence uses publicly available sources to gather information about targets, infrastructure, people, and exposures.
- D. Social media OSINT gathers information from public or accessible social platforms about people, roles, technologies, locations, or business activity.
Active reconnaissance directly interacts with targets or target-controlled infrastructure to gather information. This is the correct answer.
Which option correctly defines Passive reconnaissance?
- A. Reverse DNS lookups query for names associated with an IP address.
- B. Passive reconnaissance gathers information without directly interacting with the target’s systems.
- C. Cached pages preserve earlier versions of web pages that may reveal removed content, endpoints, technologies, or exposed information.
- D. Cryptographic flaws are weaknesses in certificates, protocols, keys, or cryptographic implementations that may reveal risk during information gathering.
Passive reconnaissance gathers information without directly interacting with the target’s systems. This is the correct answer.
A tester is gathering target information with Active reconnaissance in mind. Which choice best describes the technique?
- A. TCP/UDP scanning should be selected when the reconnaissance or enumeration scenario matches this purpose: TCP/UDP scanning probes transmission control protocol or user datagram protocol ports to identify open, closed, or filtered services.
- B. Active reconnaissance should be selected when the reconnaissance or enumeration scenario matches this purpose: Active reconnaissance directly interacts with targets or target-controlled infrastructure to gather information.
- C. Certificate transparency logs should be selected when the reconnaissance or enumeration scenario matches this purpose: Certificate transparency logs reveal issued certificates for domains and subdomains, helping identify assets and services.
- D. Information disclosure should be selected when the reconnaissance or enumeration scenario matches this purpose: Information disclosure occurs when systems, services, pages, errors, headers, or files reveal useful internal or sensitive details.
Active reconnaissance directly interacts with targets or target-controlled infrastructure to gather information. This matches the reconnaissance or enumeration scenario without shifting to a related but different source, tool, script, or technique. This is the correct answer.
A tester is gathering target information with Passive reconnaissance in mind. Which choice best describes the technique?
- A. OT protocol sniffing should be selected when the reconnaissance or enumeration scenario matches this purpose: OT protocol sniffing observes operational technology communications to identify industrial protocols, devices, and process-related traffic.
- B. Banner grabbing should be selected when the reconnaissance or enumeration scenario matches this purpose: Banner grabbing collects service banners or responses that reveal software, version, platform, or configuration details.
- C. Passive reconnaissance should be selected when the reconnaissance or enumeration scenario matches this purpose: Passive reconnaissance gathers information without directly interacting with the target’s systems.
- D. HTML scraping should be selected when the reconnaissance or enumeration scenario matches this purpose: HTML scraping extracts information from web page markup, links, comments, forms, metadata, or embedded content.
Passive reconnaissance gathers information without directly interacting with the target’s systems. This matches the reconnaissance or enumeration scenario without shifting to a related but different source, tool, script, or technique. This is the correct answer.
A tester is gathering target information with OSINT in mind. Which choice best describes the technique?
- A. Directory enumeration should be selected when the reconnaissance or enumeration scenario matches this purpose: Directory enumeration discovers web directories, files, paths, or hidden application resources.
- B. Host discovery should be selected when the reconnaissance or enumeration scenario matches this purpose: Host discovery identifies live systems or devices within a target range or environment.
- C. Share enumeration should be selected when the reconnaissance or enumeration scenario matches this purpose: Share enumeration identifies network shares, accessible resources, permissions, and exposed files.
- D. OSINT should be selected when the reconnaissance or enumeration scenario matches this purpose: Open-source intelligence uses publicly available sources to gather information about targets, infrastructure, people, and exposures.
Open-source intelligence uses publicly available sources to gather information about targets, infrastructure, people, and exposures. This matches the reconnaissance or enumeration scenario without shifting to a related but different source, tool, script, or technique. This is the correct answer.
A scoped engagement requires the safest useful way to gather information without confusing active, passive, OSINT, DNS, or traffic-based methods. Which scenario best matches Active reconnaissance?
- A. A scenario matches DNS enumeration when the tester needs this distinction: DNS enumeration identifies domain records, subdomains, name servers, mail records, zone data, and related DNS assets.
- B. A scenario matches Directory enumeration when the tester needs this distinction: Directory enumeration discovers web directories, files, paths, or hidden application resources.
- C. A scenario matches Active reconnaissance when the tester needs this distinction: Active reconnaissance directly interacts with targets or target-controlled infrastructure to gather information.
- D. A scenario matches Host discovery when the tester needs this distinction: Host discovery identifies live systems or devices within a target range or environment.
Active reconnaissance directly interacts with targets or target-controlled infrastructure to gather information. This distinction matters because choosing a nearby concept would change the source of data, level of interaction, enumeration target, script behavior, or tool selection. This is the correct answer.
A scoped engagement requires the safest useful way to gather information without confusing active, passive, OSINT, DNS, or traffic-based methods. Which scenario best matches Passive reconnaissance?
- A. A scenario matches Permission enumeration when the tester needs this distinction: Permission enumeration identifies access rights, privileges, roles, group membership, and allowed actions.
- B. A scenario matches Secrets enumeration when the tester needs this distinction: Secrets enumeration searches for exposed credentials, tokens, keys, or other sensitive access materials.
- C. A scenario matches Cloud access keys when the tester needs this distinction: Cloud access keys are credentials used to access cloud provider services or APIs.
- D. A scenario matches Passive reconnaissance when the tester needs this distinction: Passive reconnaissance gathers information without directly interacting with the target’s systems.
Passive reconnaissance gathers information without directly interacting with the target’s systems. This distinction matters because choosing a nearby concept would change the source of data, level of interaction, enumeration target, script behavior, or tool selection. This is the correct answer.
A senior tester must avoid unnecessary target interaction while still collecting useful intelligence. Which answer applies Active reconnaissance most accurately?
- A. Attack path mapping is the best answer when the discovery or enumeration decision depends on this exact meaning: Attack path mapping identifies how discovered assets, permissions, identities, and weaknesses could be chained to reach objectives.
- B. WAF enumeration is the best answer when the discovery or enumeration decision depends on this exact meaning: Web application firewall enumeration identifies whether a WAF is present and how it behaves or filters requests.
- C. Origin address is the best answer when the discovery or enumeration decision depends on this exact meaning: An origin address is the backend server address behind a proxy, CDN, or WAF that may bypass front-end protections if exposed.
- D. Active reconnaissance is the best answer when the discovery or enumeration decision depends on this exact meaning: Active reconnaissance directly interacts with targets or target-controlled infrastructure to gather information.
Active reconnaissance directly interacts with targets or target-controlled infrastructure to gather information. This applies the concept at the decision point where the wrong term would produce incomplete discovery, unnecessary target contact, poor validation, or the wrong reconnaissance workflow. This is the correct answer.
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/comptia-pentest-plus/reconnaissance-and-enumeration/
<a href="https://quizbuffet.com/comptia-pentest-plus/reconnaissance-and-enumeration/">CompTIA PenTest+ Reconnaissance and Enumeration practice quiz on QuizBuffet</a>
Other PT0-003 Domains
- Engagement Management
- Vulnerability Discovery and Analysis
- Attacks and Exploits
- Post-exploitation and Lateral Movement
← Back to PT0-003 practice test overview
Questions are written against the published PT0-003 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.