20+ practice questions focused on Reconnaissance — one of the most tested topics on the GIAC Penetration Tester exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Reconnaissance PracticeYou are performing passive reconnaissance on a target organization. You decide to query DNS records to find subdomains that might be out of scope for the primary security team. Which tool is most effective for extracting subdomains via DNS zone transfers and brute-forcing common records?
Explanation: Passive reconnaissance relies on existing public records without directly interacting with target services. DNS enumeration is a critical phase for mapping the attack surface. While zone transfers are often disabled, tools like sublist3r or fierce utilize various techniques to identify hidden subdomains. Understanding how to query DNS without alerting the target is fundamental for a penetration tester to build an initial asset inventory before moving to active scanning phases.
During passive reconnaissance, you are analyzing an organization's public DNS records. Which THREE of the following record types are most useful for identifying infrastructure details?
Explanation: DNS records provide a map of an organization's digital presence. Identifying mail servers, authoritative name servers, and service-specific hostnames is a vital part of reconnaissance. By analyzing these records, a tester can determine how traffic flows and where services are hosted. These records form the basis for further exploration and target selection during the engagement. Knowing what each record type signifies is essential for professional network reconnaissance.
You are tasked with gathering intelligence on an organization's cloud infrastructure. Which TWO of the following techniques would be most effective for discovering cloud-hosted assets?
Explanation: Cloud reconnaissance requires techniques that look beyond traditional on-premise IP ranges. By using tools to enumerate subdomains and examining DNS records for cloud-specific naming patterns, a tester can map cloud assets. Cloud providers often use unique identifiers in DNS that can be used to confirm the hosting provider. Mastering these cloud-centric reconnaissance techniques is necessary for modern engagements where the perimeter is increasingly distributed across various cloud service providers.
You are performing passive reconnaissance on a target organization. You decide to search for leaked credentials and sensitive configuration files indexed by public search engines. Which tool is most effective for automating advanced dorking queries to identify exposed administrative interfaces?
Explanation: Google Hacking Database (GHDB) queries are essential for uncovering misconfigured servers, directory listings, and exposed administrative portals. By using specialized search operators, testers bypass conventional site navigation to locate hidden infrastructure. This reconnaissance phase is vital because it reveals publicly accessible attack vectors without ever sending a packet directly to the target, minimizing the risk of triggering intrusion detection systems while maximizing the potential for discovering high-value vulnerabilities early in the engagement.
You are performing passive reconnaissance against a target organization that uses a cloud-based email service. You want to identify employee email addresses and verify which ones are valid without triggering alerting mechanisms. Which TWO of the following techniques would best accomplish this? (Choose two.)
Explanation: Passive email enumeration and verification should avoid direct interaction with the target. Public sources like LinkedIn provide candidate addresses, and third-party services can validate them using their own infrastructure. This approach minimizes the risk of alerting the target and keeps your activities stealthy. Direct SMTP commands or test emails are active and likely to be logged.
+15 more Reconnaissance questions available
Practice all Reconnaissance questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Reconnaissance. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Reconnaissance questions on the GPEN frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Reconnaissance is tested as part of the GIAC Penetration Tester blueprint. Practicing with targeted Reconnaissance questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free GPEN practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Reconnaissance is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Reconnaissance practice session with instant scoring and detailed explanations.
Start Reconnaissance Practice →