CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisMedium
A tester is conducting passive cloud reconnaissance and wants to identify a client's internet-facing devices, exposed services, and misconfigured cloud assets without sending any direct traffic to those assets. Which tool should the tester use?
- AKismet
- BShodan
- CMetasploit db_nmap
- DBurp Suite Repeater
Show answer & explanationAnswer & explanation
Correct answer: B. Shodan
Shodan is a search engine that indexes internet-connected devices and services, allowing passive discovery of exposed assets without directly scanning or interacting with the target.
Why the other options are wrong
- A. Kismet is a wireless sniffing tool, not a cloud/internet search engine.
- C. db_nmap actively scans hosts and stores results, which is not passive.
- D. Burp Repeater sends crafted requests directly, which is active testing.
Shodan
A search engine that indexes banners and metadata from internet-connected devices, enabling passive reconnaissance of exposed assets.
- Searches by IP, port, service banner, or organization
- Useful for finding exposed IoT, cloud, and industrial devices
- No direct interaction with target required
Memory trick: 'Shodan Sees Without Touching'