Be able to perform passive and active reconnaissance with DNS tools, metadata harvesters, and OSINT sources, then interpret what leaked hostnames, usernames, and metadata reveal. The most important thing is knowing which techniques stay passive and which generate traffic to the target.
Start practicing
Reconnaissance — choose a session length
Free · No account required
Domain overview
Reconnaissance on the GPEN exam covers passive and active information gathering against a target before exploitation. You must know how OSINT, DNS interrogation, metadata harvesting, and email/username enumeration work, which tools produce which artifacts, and how to interpret findings like leaked hostnames or internal IPs without touching the client's internal network.
Exam objectives
Using whois, dig, host, and nslookup to enumerate DNS records and identify split-horizon discrepancies
Harvesting document metadata with tools like FOCA, metagoofil, or exiftool to extract usernames, paths, and software versions
Collecting employee names via LinkedIn and OSINT sources to build email address patterns for validation
Distinguishing passive reconnaissance techniques from active scanning and explaining the risk tradeoffs of each
Assuming split-horizon DNS can be enumerated by querying the internal resolver directly, which sends traffic to the client's internal network and violates scope
Treating metadata disclosure as low risk when it commonly leaks internal hostnames, usernames, software versions, and filesystem paths useful for later attacks
Confusing passive OSINT collection with active verification, such as sending email or probes to validate addresses, which crosses into active reconnaissance
Click any question to see the full explanation and answer options, or start a focused practice session above.
During OSINT gathering, you are investigating a target's presence on social media and professional networking sites. Which TWO of the following methods are effective for gathering metadata about employees to facilitate future social engineering attacks?
2Which of the following describes the purpose of using Google Dorks during the reconnaissance phase of a penetration test?
3When mapping a target's network infrastructure, why is it important to use multiple WHOIS and regional internet registry (RIR) databases?
4You are analyzing the results of a passive reconnaissance scan using a tool that harvests metadata from files found on a company website. What is the primary security risk associated with this information disclosure?
5Why is it important to perform reconnaissance from a non-attributable source during a penetration test?
6During the reconnaissance phase, you notice a target is using an older, unpatched version of a popular CMS. What is the most appropriate next step?
7What is the primary benefit of using passive reconnaissance before initiating active scanning?
8You are performing a reconnaissance task and need to identify the physical location or ownership of an organization's IP space. Which TWO of the following services are standard for this task?
9During a reconnaissance project, you use the 'theHarvester' tool against a target. What information is this tool designed to extract?
10You are conducting an external penetration test against a client who uses a split-horizon DNS configuration. You want to identify internal hostnames and IP addresses without sending any traffic to the client's internal network. Which of the following techniques would best accomplish this?
11You are conducting a penetration test for a client and need to enumerate subdomains of example.com to map their external attack surface. During this reconnaissance phase, you decide to use a tool that performs DNS zone transfers. Which of the following is the most appropriate tool to attempt a DNS zone transfer?
12During the reconnaissance phase of a penetration test, you are examining a target's public-facing web application. You notice that the application returns detailed error messages that include full file paths and database query snippets. Which of the following best describes the primary risk associated with this finding?
13You are tasked with gathering information about a target organization's employees to craft a phishing campaign. Which of the following tools is specifically designed to collect email addresses, subdomains, and hostnames from public sources like search engines and PGP key servers?
14During a penetration test, you are performing passive reconnaissance against a target organization. You want to gather information about the organization's public-facing infrastructure without directly interacting with their systems. Which two of the following techniques are considered passive reconnaissance? (Choose two.)
15You are conducting external reconnaissance against a target that uses a split-horizon DNS configuration. From the public internet, you query the organization's authoritative name server for the A record of vpn.contoso.com and receive NXDOMAIN. However, you have obtained a leaked internal zone file that shows the same hostname resolving to 10.10.10.50. Which technique would best allow you to identify additional internal-only hostnames without sending traffic to the target's internal network?
16You are conducting a penetration test and have gained access to a target's internal network. You want to perform reconnaissance to identify other live hosts and services without using traditional port scanning that might trigger IDS alerts. Which of the following techniques would be most effective for low-noise host discovery on the internal network?
17You are reviewing the scope of an upcoming penetration test and need to identify the organization's mail exchangers and the servers authoritative for its DNS zones using only publicly available records. Which DNS record types should you query to obtain this information directly?
18You are performing OSINT on a target and have collected a list of employee names from LinkedIn. You want to generate likely corporate email addresses and then verify which ones are valid without sending email to the target's mail servers. Which approach best accomplishes this?
19You are conducting passive reconnaissance against a target organization and want to identify internet-facing systems and services without sending any packets to the target's own IP space. Which two techniques best satisfy this requirement? (Choose two.)
20You are performing passive reconnaissance on a target organization that uses a cloud-based email service. You want to gather information about the organization's email infrastructure and potential phishing targets without alerting the target. Which TWO of the following techniques would be most effective and appropriate for this goal? (Choose two.)
21You are conducting passive reconnaissance against a target that uses a Web Application Firewall (WAF) and a Content Delivery Network (CDN). You want to discover the origin IP address of the web server to bypass the CDN during later testing. Which technique is most likely to reveal the origin IP without sending any traffic to the target's domain?
22During a penetration test, you are reviewing the results of a WHOIS query for a target domain. You notice the registrant's email address is privacy-protected, but the technical contact email is a generic address at a third-party hosting company. What is the most likely explanation for this finding, and what should you do next to gather more information about the target's infrastructure?
Be able to perform passive and active reconnaissance with DNS tools, metadata harvesters, and OSINT sources, then interpret what leaked hostnames, usernames, and metadata reveal. The most important thing is knowing which techniques stay passive and which generate traffic to the target.
The Courseiva GPEN question bank contains 22 questions in the Reconnaissance domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Reconnaissance domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included