CompTIA PenTest+ (PT0-003)Attacks and ExploitsEasy

A penetration tester is performing reconnaissance against a target organization's public-facing web infrastructure. The tester wants to identify all subdomains associated with example.com, including those that might not be directly linked from the main website. Which of the following Nmap commands would be most effective for this task?

  1. Anmap --script dns-brute --script-args dns-brute.domain=example.com example.com
  2. Bnmap -p 80,443 --script http-enum example.com
  3. Cnmap -Pn --script hostmap example.com
  4. Dnmap -sV -p- example.com
Show answer & explanation

Correct answer: A. nmap --script dns-brute --script-args dns-brute.domain=example.com example.com

The dns-brute Nmap script is specifically designed to enumerate subdomains by brute-forcing common subdomain names and checking DNS records. This is the most direct and effective method among the options for identifying potentially hidden subdomains.

Why the other options are wrong

  • B. The http-enum script enumerates web server directories and files, not subdomains.
  • C. The hostmap script attempts to discover alternative hostnames for a target, but dns-brute is more focused on direct subdomain enumeration.
  • D. This command performs a version scan on all ports, which is not directly aimed at subdomain enumeration.

Nmap DNS Brute-Force

A method using Nmap's 'dns-brute' script to discover subdomains by systematically guessing common subdomain names and querying DNS records.

  • Uses a built-in wordlist of common subdomains.
  • Checks for A, AAAA, and CNAME records.
  • Can be slow if run against many domains or with large wordlists.

Memory trick: DNS Brute-force is your key to unlocking hidden subdomain doors.

More Attacks and Exploits questions