Topic module

Passive, Active Reconnaissance and Enumeration

Reconnaissance and enumeration questions cover passive research, OSINT, DNS, network discovery, service identification, web enumeration, cloud assets, and evidence handling.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for CompTIA PenTest+

Treat each PenTest+ item as an authorized-assessment decision: confirm scope, select safe evidence, validate risk, stop at the right point, and report remediation.

Core concepts

Concept 1

Passive reconnaissance gathers information without directly probing client systems.

Exam cue: Separate passive OSINT from active probing.

Concept 2

Active reconnaissance and enumeration interact with targets and must follow the agreed test window and scope.

Exam cue: Match tool choice to authorized target and needed evidence.

Concept 3

Enumeration should turn broad target lists into validated systems, services, versions, users, and likely attack paths.

Exam cue: Record service, version, exposure, and context without overstepping scope.

Risk pitfalls and guardrails

Performing active scans when only passive recon is authorized.

Guardrail: Avoid answers that exceed scope, skip authorization, use destructive proof, collect unnecessary sensitive data, or leave artifacts behind.

Treating one open port as proof of exploitable risk.

Guardrail: Avoid answers that exceed scope, skip authorization, use destructive proof, collect unnecessary sensitive data, or leave artifacts behind.

Ignoring cloud and third-party scope boundaries during asset discovery.

Guardrail: Avoid answers that exceed scope, skip authorization, use destructive proof, collect unnecessary sensitive data, or leave artifacts behind.

Memory anchors

OSINT

Open-source intelligence gathers publicly available information relevant to the engagement.

DNS Enumeration

DNS enumeration identifies domains, records, naming patterns, and possible infrastructure.

WHOIS

WHOIS can reveal registration, ownership, contacts, and nameserver information.

Passive Recon

Passive recon avoids direct interaction with in-scope targets.

Active Recon

Active recon sends probes or requests to authorized targets.

Port Scan

A port scan identifies reachable services but does not by itself prove exploitation.

Service Enumeration

Service enumeration identifies protocols, banners, versions, and configuration clues.

Web Enumeration

Web enumeration maps paths, technologies, parameters, headers, and authentication surfaces.

Cloud Asset

Cloud asset discovery must respect account ownership, provider rules, and client authorization.

Evidence Log

An evidence log records what was observed, when, where, and under what scope.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

Which activity is an example of passive reconnaissance?

A tester wants to discover subdomains of example.com without sending traffic to the organization's own servers. Which source is most appropriate?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.