CEH Footprinting, Reconnaissance and Scanning Practice Question
A security analyst wants to gather information about a target domain using public records without directly interacting with the target's systems. Which technique is the analyst employing?
⚠ Common exam trap
EC-Council often tests the distinction between active and passive reconnaissance, and the trap here is that candidates confuse WHOIS queries with active techniques because they involve sending a query, but since the query goes to a public third-party database (not the target's systems), it remains passive.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
OSINT using WHOIS queries
OSINT (Open Source Intelligence) using WHOIS queries is a passive reconnaissance technique that gathers domain registration details from public WHOIS databases without interacting with the target's systems. This aligns with the requirement to use public records and avoid direct contact, making it the correct choice for footprinting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Vulnerability scanning
Why it's wrong here
Vulnerability scanning involves actively sending specially crafted packets or requests to target systems and services to identify known security flaws and misconfigurations. This process directly interacts with the target's network stack and applications, making it an active form of reconnaissance rather than a passive information gathering technique. It aims to discover specific weaknesses, not general public information.
- ✓
OSINT using WHOIS queries
Why this is correct
OSINT (Open Source Intelligence) using WHOIS queries is a highly effective passive information gathering technique. It involves querying public databases to retrieve domain registration details such as registrant names, contact information, registration and expiration dates, and nameservers. This method is considered passive because it does not directly interact with the target's live systems or network, relying solely on publicly available records.
- ✗
Active reconnaissance
Why it's wrong here
Active reconnaissance involves direct, intrusive interaction with the target's systems and network infrastructure to gather information. Techniques include port scanning, ping sweeps, banner grabbing, and network mapping, all of which send packets directly to the target, potentially leaving traces and triggering defensive mechanisms. While it gathers information, it is not a passive method and carries a higher risk of detection.
- ✗
Social engineering
Why it's wrong here
Social engineering is a manipulation technique that exploits human psychology to trick individuals into divulging confidential information or performing actions that compromise security. This method relies on deception, persuasion, and psychological tactics rather than technical exploits or querying publicly available data sources. It directly targets human vulnerabilities, not digital infrastructure or public records.
Go deeper
Related to this question
Learn chapter
Footprinting and Reconnaissance
Key term
Passive reconnaissance
Passive reconnaissance is the process of gathering information about a target system or network without directly interacting with it, using publicly available sources and stealthy observation.
Key term
OSINT Techniques
OSINT techniques are methods used to collect information from publicly available sources for security assessments or investigations.
About these practice questions
One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.