Courseiva

CEH Footprinting, Reconnaissance and Scanning Practice Question

A security analyst is conducting passive reconnaissance against a target organization. The analyst wants to enumerate subdomains without sending any packets directly to the target's infrastructure, relying instead on publicly available data. Which technique BEST fits this requirement?

⚠ Common exam trap

Watch out — candidates often confuse DNS enumeration techniques that query public records with those that actively query the target's own DNS servers, which would violate the passive-only requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Querying Certificate Transparency logs for the target domain

Certificate Transparency logs are publicly accessible and contain certificate details, including subdomains listed in SAN fields. Querying these logs requires no direct contact with the target's systems, making it a purely passive technique. This satisfies the analyst's need to enumerate subdomains without sending any packets to the target's infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Running Nmap with the dns-brute script against the target's public IP range

    Why it's wrong here

    The Nmap dns-brute script performs active DNS enumeration by sending queries to the target's DNS servers. It requires direct network interaction with the target, which contradicts the passive reconnaissance requirement. Even though it can discover subdomains, the traffic generated would be visible to the target and violates the constraint of not sending packets to their infrastructure.

  • ✗

    Performing a DNS zone transfer against the target's authoritative name server

    Why it's wrong here

    A DNS zone transfer (AXFR) requires sending a query directly to the target's authoritative name server. Even if the transfer is refused, the attempt itself is an active probe that touches the target's infrastructure and may be logged. This violates the passive-only constraint, as it involves direct communication with the target's DNS servers rather than relying solely on public data sources.

  • ✓

    Querying Certificate Transparency logs for the target domain

    Why this is correct

    Certificate Transparency (CT) logs are public, append-only records of issued TLS certificates. Querying them via services like crt.sh reveals subdomains that appear in certificate Subject Alternative Name fields, without any direct interaction with the target's servers. This is purely passive and aligns with the requirement to avoid sending packets to the target infrastructure, making it the best fit for the scenario.

  • ✗

    Using a subdomain brute-force tool with a wordlist against the target's DNS resolvers

    Why it's wrong here

    Subdomain brute-forcing sends numerous DNS queries to the target's resolvers, which is an active technique. It directly interacts with the target's DNS infrastructure and can be detected or rate-limited. Since the scenario explicitly requires no packets sent to the target's infrastructure, this approach fails the passive requirement and is therefore incorrect for this task.

About these practice questions

One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.