Courseiva
Security Concepts →hardMultiple Choice

200-201 Security Concepts Practice Question

During a penetration test, a security engineer uses publicly available information from LinkedIn and Google to gather details about employees and organizational structure. Which type of reconnaissance is being performed?

⚠ Common exam trap

Cisco often tests the distinction between active and passive reconnaissance by describing an activity that uses public sources but might seem 'active' to a novice; the trap here is confusing passive information gathering with active scanning or social engineering.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Passive reconnaissance

The security engineer is gathering information from publicly available sources (LinkedIn, Google) without directly interacting with the target's systems. This is the definition of passive reconnaissance, which involves collecting data from open-source intelligence (OSINT) without sending any packets to the target network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Active reconnaissance

    Why it's wrong here

    Active reconnaissance sends traffic directly to target systems, such as port scans or DNS queries, generating logs and detectable footprints; LinkedIn and Google queries touch third-party public sources instead. It is tempting because reconnaissance ultimately feeds active testing, but this scenario's passive collection of publicly posted employee data matches OSINT, not active probing.

  • ✗

    Social engineering

    Why it's wrong here

    Social engineering involves manipulating people into divulging information or performing actions, typically through phishing or pretexting; merely reading public LinkedIn and Google pages involves no human interaction or deception. It is tempting because the collected employee details could later support a social engineering campaign, but the reconnaissance activity itself is passive and OSINT-based.

  • ✓

    Passive reconnaissance

    Why this is correct

    Passive reconnaissance relies on publicly available sources without directly interacting with the target's systems, so no packets reach the organisation's infrastructure. LinkedIn and Google searches match this exactly, satisfying the stem's constraint of gathering employee and structural details covertly, leaving no trace in the target's logs.

  • ✗

    Internal reconnaissance

    Why it's wrong here

    Internal reconnaissance is conducted from within the target's network, using internal scanning or compromised hosts; LinkedIn and Google are external, publicly accessible sources. It is tempting because the gathered employee and structure data could inform an insider-style assessment, but internal reconnaissance requires an existing foothold on the organisation's systems, which this scenario lacks.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.