CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationEasy
A penetration tester is conducting a passive reconnaissance phase against a target organization. They are focusing on identifying subdomains without directly interacting with the target's servers. Which of the following techniques would be most effective for this purpose?
- ARunning an Nmap scan with the -p- flag against the main domain.
- BPerforming a brute-force DNS enumeration using a wordlist.
- CQuerying public DNS records via online tools or search engines.
- DUsing nslookup to perform zone transfers.
Show answer & explanationAnswer & explanation
Correct answer: C. Querying public DNS records via online tools or search engines.
Querying public DNS records via online tools or search engines (like Google Dorks) is a passive method, as it relies on information already publicly available and does not directly interact with the target's DNS servers, thus avoiding detection.
Why the other options are wrong
- A. Nmap scans directly interact with the target's network, making it an active reconnaissance technique.
- B. Brute-force DNS enumeration involves sending numerous queries to the target's DNS server, making it an active and potentially noisy technique.
- D. Zone transfers are active reconnaissance as they directly query the target's DNS server and are often restricted, which can trigger alerts.
Passive DNS Enumeration
Gathering DNS information about a target without direct interaction, relying on publicly available data from third-party sources.
- Uses search engines, public archives, and OSINT tools.
- Minimizes detection risk.
- Examples: Google dorking, querying VirusTotal, Shodan.
Memory trick: DNS: Passive, Active, Zone, Brute.