200-201 Security Concepts Practice Question
A security engineer is analyzing a recent data breach. Which TWO are examples of active reconnaissance techniques? (Select two.)
⚠ Common exam trap
The trap is misclassifying OSINT techniques like WHOIS, Google dorking, and social media profiling as active — candidates forget that 'active' specifically means sending traffic to the target, not just gathering information about it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Port scanning
Port scanning (A) is an active reconnaissance technique because it sends TCP/UDP probes (e.g., SYN, ACK, or UDP packets via tools like Nmap) directly to target hosts to discover open ports and services, which interacts with the target and can be logged. Ping sweep (B) is also active reconnaissance because it transmits ICMP Echo Request packets (or ARP/TCP probes) across an IP range to identify live hosts, again directly engaging the target network. By contrast, LinkedIn profiling (C), WHOIS lookup (D), and Google dorking (E) are passive reconnaissance techniques, as they gather information from third-party sources or public records without sending traffic to the target's systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Port scanning
Why this is correct
Port scanning actively probes target hosts to discover open ports and running services, generating traffic that touches the target directly, which defines active reconnaissance. It contrasts with passive techniques such as searching public records or monitoring traffic, where the attacker never interacts with the target's systems.
- ✓
Ping sweep
Why this is correct
A ping sweep sends ICMP echo requests to hosts across a range, directly interacting with targets to map live systems. This active traffic generation distinguishes it from passive reconnaissance, which relies on indirect sources, and satisfies the stem's requirement for an active technique.
- ✗
LinkedIn profiling
Why it's wrong here
LinkedIn profiling gathers public information without touching the target's systems, making it passive reconnaissance. It tempts because it genuinely supports attacker planning, and would be correct if the question instead asked for passive reconnaissance techniques, where OSINT on employees and roles qualifies.
- ✗
WHOIS lookup
Why it's wrong here
WHOIS queries public registry records rather than interacting with the target's infrastructure, so it is passive reconnaissance. It tempts because it is a standard early-stage information-gathering step, and would be correct if the question asked which techniques avoid direct contact with target systems.
- ✗
Google dorking
Why it's wrong here
Google dorking queries search engine indexes, never the target's own hosts, so it remains passive reconnaissance. It tempts because it uncovers exposed files and pages, and would be correct if the question asked for passive OSINT techniques rather than techniques that directly probe target systems.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.