200-201 Security Concepts Practice Question
An attacker uses a tool to scan all IP addresses in a range to identify which hosts are online and what services are running. Which type of reconnaissance is this?
⚠ Common exam trap
200-201 often tests the distinction between active and passive reconnaissance; the trap is that candidates may confuse scanning (active) with monitoring (passive) and select the wrong type.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Active reconnaissance
Active reconnaissance involves directly interacting with the target system to gather information, such as scanning IP addresses to identify live hosts and open services. This type of scanning generates traffic that can be detected by the target, distinguishing it from passive reconnaissance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Active reconnaissance
Why this is correct
Active reconnaissance involves directly interacting with targets, such as scanning IP ranges to elicit responses revealing live hosts and services. This matches the stem's constraint: the attacker's scanning traffic touches the target, unlike passive reconnaissance, which only observes third-party data.
- ✗
Denial of Service
Why it's wrong here
Denial of Service floods or exhausts a target to disrupt availability; it gathers no host or service inventory. It tempts because both are attacker activities, but scanning a range to enumerate live hosts and open services is active reconnaissance, not traffic flooding.
- ✗
Passive reconnaissance
Why it's wrong here
Active scanning sends packets to each host and reads responses, so it is active reconnaissance, not passive. Passive reconnaissance gathers intelligence from third-party sources, such as WHOIS records, DNS lookups or public breach data, without touching the target's systems directly.
- ✗
Social engineering
Why it's wrong here
Social engineering manipulates people into revealing information, whereas scanning IP ranges is direct technical probing of network hosts. It tempts because both are reconnaissance techniques, but social engineering targets human trust, not host and service discovery across an address range.
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.