
CompTIAPenTest+
Domain 2Objective 1
Active and Passive Reconnaissance PT0-003 Practice Questions (Page 5)
Part of the Reconnaissance and enumeration domain, which accounts for 21% of the PT0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~14–23 in this domain), expect 4–6 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
6concepts
21%of the exam
Questions 21–25
- 21
After identifying that a target host has port 80 open, a penetration tester wants to determine the specific web server software and version running. Which technique is most appropriate?
Select an answer first - 22
A penetration tester wants to capture network traffic on a switched network segment to analyze the data being transmitted. Which tool is specifically designed for network sniffing?
Select an answer first - 23
Which of the following is an example of service enumeration?
Select an answer first - 24
A penetration tester is building a profile of a target organization using only open-source intelligence. The tester wants to identify the organization's physical locations and key personnel. Which combination of OSINT sources would provide the most comprehensive information?
Select an answer first - 25
A penetration tester is conducting passive reconnaissance on a target organization. The tester wants to identify the organization's cloud service provider and the regions where they host their infrastructure, without directly querying the target's systems. Which OSINT technique would be most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “PT0-003” is a trademark of its owner, used for identification only.