📖 What is Whois?

Whois is a query and response protocol used for searching databases that store the registered users or assignees of an internet resource, such as a domain name or an IP address block. It provides essential reconnaissance data, including registrant contact information.

🥋 Sensei Says:

"Be aware that Whois Privacy services often mask this data. If the data is redacted, you will need to pivot to other OSINT techniques."

📚 Certification: CompTIA PenTest+ (PT0-002)

🔑 What are the Key Concepts of Whois?

  • Registrar and Registrant Data: Whois reveals the entity that registered the domain and the company that sold it, helping identify the target's infrastructure providers.
  • Name Server Identification: Identifying authoritative name servers allows a tester to determine if the target uses third-party DNS or manages their own infrastructure.
  • IP Address Allocation: Whois queries for IP blocks through regional registries like ARIN or RIPE help testers identify the organization owning a specific network range.
  • Registration Timelines: Analyzing registration and expiration dates provides clues about the age of a domain or potential windows for domain hijacking and expiration attacks.
  • RDAP Integration: Registration Data Access Protocol (RDAP) is the modern, standardized successor to Whois, providing machine-readable data via HTTP instead of a custom port.

🎯 How does Whois appear on the PT0-002 Exam?

You may be asked to identify the best tool for passive reconnaissance to find the administrative contact and registration date of a target domain without interacting with the server.

A scenario might describe a need to map out an organization's network footprint; you would use Whois to find the IP address blocks assigned to that specific entity.

Expect questions where you must determine the next step after finding that a target's Whois record is redacted by a privacy service, requiring a pivot to other OSINT tools.

❓ Frequently Asked Questions

Is Whois considered active or passive reconnaissance?

Whois is passive reconnaissance because you are querying a third-party database maintained by a registrar or registry rather than interacting directly with the target's own servers.


How does Whois differ from a DNS query like dig or nslookup?

Whois retrieves registration and ownership data from a registrar, whereas DNS queries retrieve technical routing records (like A, MX, or TXT records) from the DNS system.


What should a tester do if Whois privacy is enabled?

When data is redacted, testers should pivot to other OSINT techniques, such as searching social media, using search engine dorks, or analyzing SSL/TLS certificate details for clues.

Related Terms from CompTIA PenTest+

📝 Related Study Guides

Comparison 8 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

Choose CISSP if you want broad technical security expertise across eight domains, including cryptography, network security, and software development. Choose CISM if you're focused on information security management, governance, and risk management from a leadership perspective. CISSP is ideal for hands-on security architects, while CISM is designed for security managers and directors.

Career Guide 9 min read

The IT Certification Roadmap: Where to Start in 2026

Start your IT certification journey in 2026 with CompTIA A+ for general IT foundations, then branch into networking (Network+), cybersecurity (Security+), or cloud computing (AWS Cloud Practitioner or Azure Fundamentals) based on your career goals. Each path leads to advanced certifications like CISSP, AWS Solutions Architect, or CISM within 2-3 years of focused progression.

Comparison 10 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

The CISSP is a broad, technical-to-managerial certification focusing on security operations and architecture across eight domains. In contrast, CISM is a specialized management certification centered on governance, risk management, and program development. Choose CISSP for comprehensive security expertise and CISM if you are pivoting specifically into security leadership and governance roles.

🧠

Test Your Knowledge

Think you understand Whois? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium