Courseiva
Security Concepts →mediumMultiple Choice

200-201 Security Concepts Practice Question

An attacker uses a tool to scan all IP addresses in a range to identify which hosts are online and what services are running. Which type of reconnaissance is this?

⚠ Common exam trap

200-201 often tests the distinction between active and passive reconnaissance; the trap is that candidates may confuse scanning (active) with monitoring (passive) and select the wrong type.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Active reconnaissance

Active reconnaissance involves directly interacting with the target system to gather information, such as scanning IP addresses to identify live hosts and open services. This type of scanning generates traffic that can be detected by the target, distinguishing it from passive reconnaissance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Active reconnaissance

    Why this is correct

    Active reconnaissance involves directly interacting with targets, such as scanning IP ranges to elicit responses revealing live hosts and services. This matches the stem's constraint: the attacker's scanning traffic touches the target, unlike passive reconnaissance, which only observes third-party data.

  • ✗

    Denial of Service

    Why it's wrong here

    Denial of Service floods or exhausts a target to disrupt availability; it gathers no host or service inventory. It tempts because both are attacker activities, but scanning a range to enumerate live hosts and open services is active reconnaissance, not traffic flooding.

  • ✗

    Passive reconnaissance

    Why it's wrong here

    Active scanning sends packets to each host and reads responses, so it is active reconnaissance, not passive. Passive reconnaissance gathers intelligence from third-party sources, such as WHOIS records, DNS lookups or public breach data, without touching the target's systems directly.

  • ✗

    Social engineering

    Why it's wrong here

    Social engineering manipulates people into revealing information, whereas scanning IP ranges is direct technical probing of network hosts. It tempts because both are reconnaissance techniques, but social engineering targets human trust, not host and service discovery across an address range.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.