CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationHard

A penetration tester is performing reconnaissance against a client's network. They have identified a domain name and want to discover potential subdomains by querying publicly available DNS records and using passive techniques to avoid direct interaction with the target's DNS servers. Which of the following methods is a form of passive subdomain enumeration?

  1. AQuerying Certificate Transparency (CT) logs for subdomains.
  2. BPerforming an Nmap dns-brute scan.
  3. CUsing a tool like Fierce to perform recursive DNS lookups.
  4. DRequesting a DNS zone transfer (AXFR) from the target's name servers.
Show answer & explanation

Correct answer: A. Querying Certificate Transparency (CT) logs for subdomains.

Querying Certificate Transparency (CT) logs is a passive method because it involves querying public databases (CT logs) that store records of issued SSL/TLS certificates. These certificates often contain subdomain names, and accessing the logs does not directly interact with the target's DNS infrastructure.

Why the other options are wrong

  • B. Nmap's dns-brute performs active brute-forcing against the target's DNS servers, making it an active technique.
  • C. Tools like Fierce perform active DNS queries (e.g., brute-forcing, recursive lookups) against the target's DNS servers, making it an active technique.
  • D. Requesting a zone transfer is a direct query to the target's DNS server, making it an active and often detectable technique.

Certificate Transparency (CT) Logs for Subdomain Enumeration

Certificate Transparency (CT) logs are public, auditable records of all SSL/TLS certificates issued by Certificate Authorities. Penetration testers can query these logs to passively discover subdomains that have had certificates issued for them, without directly interacting with the target's network.

  • Publicly accessible databases of SSL/TLS certificates.
  • Contains subdomain names from 'Subject Alternative Name' (SAN) fields.
  • A passive reconnaissance technique, as it doesn't touch the target's infrastructure.

Memory trick: CT logs quietly reveal subdomains from public certificates.

More Reconnaissance and Enumeration questions