Passive, Active Reconnaissance and Enumeration
Reconnaissance and enumeration questions cover passive research, OSINT, DNS, network discovery, service identification, web enumeration, cloud assets, and evidence handling.
How to study for CompTIA PenTest+
Treat each PenTest+ item as an authorized-assessment decision: confirm scope, select safe evidence, validate risk, stop at the right point, and report remediation.
Core concepts
Concept 1
Passive reconnaissance gathers information without directly probing client systems.
Exam cue: Separate passive OSINT from active probing.
Concept 2
Active reconnaissance and enumeration interact with targets and must follow the agreed test window and scope.
Exam cue: Match tool choice to authorized target and needed evidence.
Concept 3
Enumeration should turn broad target lists into validated systems, services, versions, users, and likely attack paths.
Exam cue: Record service, version, exposure, and context without overstepping scope.
Risk pitfalls and guardrails
Performing active scans when only passive recon is authorized.
Guardrail: Avoid answers that exceed scope, skip authorization, use destructive proof, collect unnecessary sensitive data, or leave artifacts behind.
Treating one open port as proof of exploitable risk.
Guardrail: Avoid answers that exceed scope, skip authorization, use destructive proof, collect unnecessary sensitive data, or leave artifacts behind.
Ignoring cloud and third-party scope boundaries during asset discovery.
Guardrail: Avoid answers that exceed scope, skip authorization, use destructive proof, collect unnecessary sensitive data, or leave artifacts behind.
Memory anchors
OSINT
Open-source intelligence gathers publicly available information relevant to the engagement.
DNS Enumeration
DNS enumeration identifies domains, records, naming patterns, and possible infrastructure.
WHOIS
WHOIS can reveal registration, ownership, contacts, and nameserver information.
Passive Recon
Passive recon avoids direct interaction with in-scope targets.
Active Recon
Active recon sends probes or requests to authorized targets.
Port Scan
A port scan identifies reachable services but does not by itself prove exploitation.
Service Enumeration
Service enumeration identifies protocols, banners, versions, and configuration clues.
Web Enumeration
Web enumeration maps paths, technologies, parameters, headers, and authentication surfaces.
Cloud Asset
Cloud asset discovery must respect account ownership, provider rules, and client authorization.
Evidence Log
An evidence log records what was observed, when, where, and under what scope.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
Which activity is an example of passive reconnaissance?
A tester wants to discover subdomains of example.com without sending traffic to the organization's own servers. Which source is most appropriate?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
