CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationEasy

A penetration tester is conducting a passive reconnaissance phase against a target organization. They are focusing on identifying subdomains without directly interacting with the target's servers. Which of the following techniques would be most effective for this purpose?

  1. ARunning an Nmap scan with the -p- flag against the main domain.
  2. BPerforming a brute-force DNS enumeration using a wordlist.
  3. CQuerying public DNS records via online tools or search engines.
  4. DUsing nslookup to perform zone transfers.
Show answer & explanation

Correct answer: C. Querying public DNS records via online tools or search engines.

Querying public DNS records via online tools or search engines (like Google Dorks) is a passive method, as it relies on information already publicly available and does not directly interact with the target's DNS servers, thus avoiding detection.

Why the other options are wrong

  • A. Nmap scans directly interact with the target's network, making it an active reconnaissance technique.
  • B. Brute-force DNS enumeration involves sending numerous queries to the target's DNS server, making it an active and potentially noisy technique.
  • D. Zone transfers are active reconnaissance as they directly query the target's DNS server and are often restricted, which can trigger alerts.

Passive DNS Enumeration

Gathering DNS information about a target without direct interaction, relying on publicly available data from third-party sources.

  • Uses search engines, public archives, and OSINT tools.
  • Minimizes detection risk.
  • Examples: Google dorking, querying VirusTotal, Shodan.

Memory trick: DNS: Passive, Active, Zone, Brute.

More Reconnaissance and Enumeration questions