CEH Footprinting, Reconnaissance and Scanning Practice Question
A security analyst is conducting passive reconnaissance against a target organization. The analyst wants to enumerate subdomains without sending any packets directly to the target's infrastructure, relying instead on publicly available data. Which technique BEST fits this requirement?
⚠ Common exam trap
Watch out — candidates often confuse DNS enumeration techniques that query public records with those that actively query the target's own DNS servers, which would violate the passive-only requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Querying Certificate Transparency logs for the target domain
Certificate Transparency logs are publicly accessible and contain certificate details, including subdomains listed in SAN fields. Querying these logs requires no direct contact with the target's systems, making it a purely passive technique. This satisfies the analyst's need to enumerate subdomains without sending any packets to the target's infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Running Nmap with the dns-brute script against the target's public IP range
Why it's wrong here
The Nmap dns-brute script performs active DNS enumeration by sending queries to the target's DNS servers. It requires direct network interaction with the target, which contradicts the passive reconnaissance requirement. Even though it can discover subdomains, the traffic generated would be visible to the target and violates the constraint of not sending packets to their infrastructure.
- ✗
Performing a DNS zone transfer against the target's authoritative name server
Why it's wrong here
A DNS zone transfer (AXFR) requires sending a query directly to the target's authoritative name server. Even if the transfer is refused, the attempt itself is an active probe that touches the target's infrastructure and may be logged. This violates the passive-only constraint, as it involves direct communication with the target's DNS servers rather than relying solely on public data sources.
- ✓
Querying Certificate Transparency logs for the target domain
Why this is correct
Certificate Transparency (CT) logs are public, append-only records of issued TLS certificates. Querying them via services like crt.sh reveals subdomains that appear in certificate Subject Alternative Name fields, without any direct interaction with the target's servers. This is purely passive and aligns with the requirement to avoid sending packets to the target infrastructure, making it the best fit for the scenario.
- ✗
Using a subdomain brute-force tool with a wordlist against the target's DNS resolvers
Why it's wrong here
Subdomain brute-forcing sends numerous DNS queries to the target's resolvers, which is an active technique. It directly interacts with the target's DNS infrastructure and can be detected or rate-limited. Since the scenario explicitly requires no packets sent to the target's infrastructure, this approach fails the passive requirement and is therefore incorrect for this task.
Go deeper
Related to this question
About these practice questions
One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.