CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationEasy

A penetration tester is performing initial reconnaissance against a target organization. They want to identify publicly exposed subdomains and associated IP addresses, but without directly querying the target's DNS servers to avoid detection. Which of the following tools or techniques would be most suitable for this passive enumeration task?

  1. AUsing 'dig axfr target.com' to perform a zone transfer.
  2. BExecuting a brute-force attack against the target's authoritative DNS servers.
  3. CQuerying Certificate Transparency logs for subdomains related to the target.
  4. DPerforming an Nmap scan with the `--dns-servers` option pointing to the target's DNS.
Show answer & explanation

Correct answer: C. Querying Certificate Transparency logs for subdomains related to the target.

Querying Certificate Transparency (CT) logs is a passive reconnaissance technique that allows the identification of subdomains without directly interacting with the target's infrastructure. These logs record all TLS/SSL certificates issued for domains, often including subdomains.

Why the other options are wrong

  • A. 'dig axfr' attempts an active zone transfer, which is often blocked and detectable.
  • B. Brute-forcing DNS servers is an active and noisy technique that can easily be detected.
  • D. Nmap with `--dns-servers` still performs active DNS queries, which can be detected by the target.

Certificate Transparency Logs

Publicly auditable logs that record all TLS/SSL certificates issued by Certificate Authorities. They are a valuable passive reconnaissance source for discovering subdomains.

  • Records all issued TLS/SSL certificates.
  • Publicly accessible and auditable.
  • Useful for passive subdomain enumeration.

Memory trick: CERTs Show Many Domain Branches

More Reconnaissance and Enumeration questions