CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisMedium

A tester is conducting passive cloud reconnaissance and wants to identify a client's internet-facing devices, exposed services, and misconfigured cloud assets without sending any direct traffic to those assets. Which tool should the tester use?

  1. AKismet
  2. BShodan
  3. CMetasploit db_nmap
  4. DBurp Suite Repeater
Show answer & explanation

Correct answer: B. Shodan

Shodan is a search engine that indexes internet-connected devices and services, allowing passive discovery of exposed assets without directly scanning or interacting with the target.

Why the other options are wrong

  • A. Kismet is a wireless sniffing tool, not a cloud/internet search engine.
  • C. db_nmap actively scans hosts and stores results, which is not passive.
  • D. Burp Repeater sends crafted requests directly, which is active testing.

Shodan

A search engine that indexes banners and metadata from internet-connected devices, enabling passive reconnaissance of exposed assets.

  • Searches by IP, port, service banner, or organization
  • Useful for finding exposed IoT, cloud, and industrial devices
  • No direct interaction with target required

Memory trick: 'Shodan Sees Without Touching'

More Vulnerability Discovery and Analysis questions