You must select the most effective reconnaissance technique for a scenario and read command output correctly. The key skill is distinguishing passive from active footprinting and knowing which tool or DNS query yields the needed information without touching the target directly.
Start practicing
Footprinting and Reconnaissance — choose a session length
Free · No account required
Domain overview
Footprinting and Reconnaissance covers passive and active information gathering against a target before exploitation: DNS and WHOIS lookups, search-engine and social-media mining, website mirroring, email header and DSN analysis, and network range discovery. Questions present a scenario or command output and ask you to pick the most effective technique, identify footprinting tools, or infer conclusions from results.
Exam objectives
Subdomain enumeration via DNS zone transfers, brute-forcing, and certificate transparency logs
WHOIS, nslookup, dig, and DNS record types (A, MX, NS, TXT, SOA)
Footprinting tool categories: search engines, email tracking, and website mirroring utilities
Email header analysis, DSN behavior, and information leaked by mail server responses
Confusing active footprinting (direct queries to the target) with passive footprinting that only uses public third-party sources.
Assuming a failed DNS zone transfer means no subdomains exist, when brute-forcing or certificate logs may still reveal them.
Treating social engineering or scanning as footprinting; this domain stops at information gathering, not exploitation or enumeration of live services.
Click any question to see the full explanation and answer options, or start a focused practice session above.
During the reconnaissance phase, a tester discovers that the target company's email server is configured to automatically respond to delivery status notifications (DSNs). Which type of attack could this information facilitate?
2A security analyst is tasked with performing passive reconnaissance on a target organization. Which of the following is the BEST approach to gather information about the target's technology stack without directly interacting with the target's systems?
3An ethical hacker wants to discover subdomains of a target domain using only public information. Which of the following techniques is MOST effective?
4Which TWO of the following are examples of passive footprinting techniques? (Select exactly 2.)
5Which THREE of the following are valid pieces of information that can be gathered from a properly configured Netcraft site report? (Select exactly 3.)
6An ethical hacker runs the command shown in the exhibit. Which of the following conclusions can be drawn from the output?
7Which TWO of the following tools are specifically designed for footprinting and reconnaissance tasks? (Select two.)
8What can be inferred from the output?
9You are a penetration tester for a security firm. Your client, Acme Corp, has requested an external reconnaissance assessment. They have provided their primary domain 'acme.com'. You begin by performing passive footprinting using public sources. After gathering initial information, you want to identify their email servers, subdomains, and any exposed services. You also want to map their network infrastructure without directly interacting with their systems to avoid detection. Which course of action should you take next?
10During a penetration test, you discover that the target organization uses a cloud-based email service. Which technique would allow you to gather employee email addresses and potentially infer internal organizational structure?
11Refer to the exhibit. An attacker runs the nslookup command shown. What information has been gathered?
12Drag and drop the steps to set up a VPN using IPsec in tunnel mode into the correct order.
13Match each CEH phase to its key activity.
14During an authorized external assessment, a tester wants to determine which mail exchangers and third-party SaaS providers a target uses without alerting the target's security team. The tester already knows the primary domain. Which single command best reveals the target's MX records using a public resolver while sending no traffic to the target itself?
15An ethical hacker is building a profile of a target organization's employees and wants to identify names, job titles, and email address formats using only information the organization has published. Which technique is BEST suited to this goal?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
You must select the most effective reconnaissance technique for a scenario and read command output correctly. The key skill is distinguishing passive from active footprinting and knowing which tool or DNS query yields the needed information without touching the target directly.
The Courseiva CEH question bank contains 15 questions in the Footprinting and Reconnaissance domain, covering the 8% of the exam attributed to this domain in the official EC-Council blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Footprinting and Reconnaissance domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included