Courseiva
Footprinting, Reconnaissance and ScanningeasyMultiple ChoiceObjective-mapped

CEH Footprinting, Reconnaissance and Scanning Practice Question

A security analyst wants to gather information about a target domain using public records without directly interacting with the target's systems. Which technique is the analyst employing?

⚠ Common exam trap

EC-Council often tests the distinction between active and passive reconnaissance, and the trap here is that candidates confuse WHOIS queries with active techniques because they involve sending a query, but since the query goes to a public third-party database (not the target's systems), it remains passive.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

OSINT using WHOIS queries

OSINT (Open Source Intelligence) using WHOIS queries is a passive reconnaissance technique that gathers domain registration details from public WHOIS databases without interacting with the target's systems. This aligns with the requirement to use public records and avoid direct contact, making it the correct choice for footprinting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Vulnerability scanning

    Why it's wrong here

    Vulnerability scanning involves actively sending specially crafted packets or requests to target systems and services to identify known security flaws and misconfigurations. This process directly interacts with the target's network stack and applications, making it an active form of reconnaissance rather than a passive information gathering technique. It aims to discover specific weaknesses, not general public information.

  • OSINT using WHOIS queries

    Why this is correct

    OSINT (Open Source Intelligence) using WHOIS queries is a highly effective passive information gathering technique. It involves querying public databases to retrieve domain registration details such as registrant names, contact information, registration and expiration dates, and nameservers. This method is considered passive because it does not directly interact with the target's live systems or network, relying solely on publicly available records.

  • Active reconnaissance

    Why it's wrong here

    Active reconnaissance involves direct, intrusive interaction with the target's systems and network infrastructure to gather information. Techniques include port scanning, ping sweeps, banner grabbing, and network mapping, all of which send packets directly to the target, potentially leaving traces and triggering defensive mechanisms. While it gathers information, it is not a passive method and carries a higher risk of detection.

  • Social engineering

    Why it's wrong here

    Social engineering is a manipulation technique that exploits human psychology to trick individuals into divulging confidential information or performing actions that compromise security. This method relies on deception, persuasion, and psychological tactics rather than technical exploits or querying publicly available data sources. It directly targets human vulnerabilities, not digital infrastructure or public records.

About these practice questions

One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.