Courseiva
Security Concepts →easyMultiple Select

200-201 Security Concepts Practice Question

A security analyst is identifying potential vulnerabilities in the network. Which TWO of the following are examples of passive reconnaissance?

⚠ Common exam trap

Cisco often tests the distinction between passive and active reconnaissance by including 'vulnerability scan' as a distractor, because candidates may mistakenly think it is passive since it can be run with minimal privileges, but it always involves direct interaction with the target.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Google search for company information

Passive reconnaissance gathers information about a target without directly interacting with its systems, so Google searches for company information (B) qualify because they use public search engines and cached data to collect OSINT such as employee names, technologies, and domains without touching the target's infrastructure. WHOIS lookup (C) is also passive because it queries public registration databases to obtain domain ownership, registrar, and contact details without sending any traffic to the target's hosts. By contrast, a vulnerability scan (A) actively probes systems for weaknesses, a ping sweep (D) sends ICMP echo requests to discover live hosts, and port scanning (E) sends TCP/UDP probes to enumerate open ports — all of which are active reconnaissance techniques that directly interact with the target and can be logged or detected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Vulnerability scan

    Why it's wrong here

    A vulnerability scan actively probes systems for known weaknesses, sending packets and eliciting responses, so it is active reconnaissance. It is tempting because scanning tools are used during assessment, but passive reconnaissance gathers intelligence from public sources such as DNS records or job postings without contacting the target.

  • ✓

    Google search for company information

    Why this is correct

    Searching public sources for company information gathers intelligence without touching the target's systems, so no packets reach the organisation and nothing is logged. That absence of direct interaction with the target satisfies the passive reconnaissance constraint in the stem.

  • ✓

    WHOIS lookup

    Why this is correct

    A WHOIS lookup queries public registry records for domain ownership, registration dates and nameservers without sending any traffic to the target's infrastructure. This satisfies the stem's passive reconnaissance constraint, since no packets reach the organisation's hosts, leaving no trace in their logs or intrusion detection systems.

  • ✗

    Ping sweep

    Why it's wrong here

    A ping sweep sends ICMP echo requests directly to hosts, generating traffic and responses that the target can observe, making it active reconnaissance. It is tempting because it is low-noise and often used early in enumeration, but any technique that interacts with the target is active, not passive.

  • ✗

    Port scanning

    Why it's wrong here

    Port scanning transmits probes to target ports and analyses replies, so it interacts directly with the target and is active reconnaissance. It is tempting because scanning is often performed quietly during early discovery, but passive reconnaissance relies solely on publicly available information without touching the target.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.