200-201 Security Concepts Practice Question
During a penetration test, a security engineer uses publicly available information from LinkedIn and Google to gather details about employees and organizational structure. Which type of reconnaissance is being performed?
⚠ Common exam trap
Cisco often tests the distinction between active and passive reconnaissance by describing an activity that uses public sources but might seem 'active' to a novice; the trap here is confusing passive information gathering with active scanning or social engineering.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Passive reconnaissance
The security engineer is gathering information from publicly available sources (LinkedIn, Google) without directly interacting with the target's systems. This is the definition of passive reconnaissance, which involves collecting data from open-source intelligence (OSINT) without sending any packets to the target network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Active reconnaissance
Why it's wrong here
Active reconnaissance sends traffic directly to target systems, such as port scans or DNS queries, generating logs and detectable footprints; LinkedIn and Google queries touch third-party public sources instead. It is tempting because reconnaissance ultimately feeds active testing, but this scenario's passive collection of publicly posted employee data matches OSINT, not active probing.
- ✗
Social engineering
Why it's wrong here
Social engineering involves manipulating people into divulging information or performing actions, typically through phishing or pretexting; merely reading public LinkedIn and Google pages involves no human interaction or deception. It is tempting because the collected employee details could later support a social engineering campaign, but the reconnaissance activity itself is passive and OSINT-based.
- ✓
Passive reconnaissance
Why this is correct
Passive reconnaissance relies on publicly available sources without directly interacting with the target's systems, so no packets reach the organisation's infrastructure. LinkedIn and Google searches match this exactly, satisfying the stem's constraint of gathering employee and structural details covertly, leaving no trace in the target's logs.
- ✗
Internal reconnaissance
Why it's wrong here
Internal reconnaissance is conducted from within the target's network, using internal scanning or compromised hosts; LinkedIn and Google are external, publicly accessible sources. It is tempting because the gathered employee and structure data could inform an insider-style assessment, but internal reconnaissance requires an existing foothold on the organisation's systems, which this scenario lacks.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.