Courseiva
Security Concepts →mediumMultiple Select

200-201 Security Concepts Practice Question

A security analyst is investigating a network breach. Which TWO activities are examples of passive reconnaissance? (Choose two.)

⚠ Common exam trap

200-201 often tests whether candidates can distinguish passive from active reconnaissance — candidates incorrectly classify WHOIS lookups as active because they involve querying a server, but WHOIS queries go to a third-party registry, not the target.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reviewing LinkedIn profiles of employees

It is passive reconnaissance: the analyst gathers publicly available employee information from social media without directly interacting with the target's systems, so no packets are sent to the organization's infrastructure. Option D (Searching WHOIS records for domain registration details) is also correct because WHOIS queries retrieve publicly registered domain ownership, contact, and nameserver data from third-party registries, again without touching the target network. By contrast, option B (ping sweeps) and option E (port scans) are active reconnaissance techniques that send ICMP echo requests or TCP/UDP probes directly to target hosts, and option C (vulnerability scanning) is active because it transmits crafted probes to identify weaknesses on the target systems.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Reviewing LinkedIn profiles of employees

    Why this is correct

    Reviewing LinkedIn profiles gathers employee names, roles and technologies without touching the target's systems, so no packets reach the organisation. This indirect, non-intrusive collection satisfies the stem's passive-reconnaissance constraint, unlike scanning or banner grabbing, which generate detectable traffic.

  • ✗

    Sending ping sweeps to identify live hosts

    Why it's wrong here

    Ping sweeps transmit ICMP echo requests to target addresses, so they are active reconnaissance that touches the network and may trigger alerts. Passive reconnaissance collects data from public sources without sending traffic to the target; ping sweeps suit authorised host-discovery phases where direct probing is allowed.

  • ✗

    Using a vulnerability scanner to find weaknesses

    Why it's wrong here

    A vulnerability scanner transmits crafted probes and analyses responses, so it interacts directly with target systems and is active reconnaissance. Passive reconnaissance relies on publicly available information without touching the target; scanning is chosen when authorised testing must enumerate weaknesses on live hosts.

  • ✓

    Searching WHOIS records for domain registration details

    Why this is correct

    WHOIS queries are answered by public registration databases, not the target's infrastructure, so no traffic reaches the organisation's hosts. This indirect, non-intrusive lookup satisfies the stem's passive-reconnaissance constraint, unlike port scanning or DNS zone transfers, which interact with target systems.

  • ✗

    Performing a port scan on the target network

    Why it's wrong here

    A port scan sends packets to target hosts and reads their replies, making it active reconnaissance that can be logged or blocked. Passive reconnaissance gathers intelligence from third-party sources without contacting the target; port scanning is correct when the engagement permits direct enumeration of exposed services.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.