Courseiva

CEH Footprinting and Reconnaissance Practice Question

An ethical hacker is building a profile of a target organization's employees and wants to identify names, job titles, and email address formats using only information the organization has published. Which technique is BEST suited to this goal?

⚠ Common exam trap

The trap here is reaching for an intrusive enumeration technique like SMTP VRFY when the scenario explicitly restricts the tester to information the organization has already published.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reviewing the organization's LinkedIn company page and employee profiles

Employee profiling from published data centers on sources the organization and its staff voluntarily expose, such as LinkedIn, corporate press releases, and conference speaker bios. Reviewing a LinkedIn company page and employee profiles passively reveals names, titles, and the email naming convention, which can then be validated against other public records without ever contacting the target's systems.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cracking the organization's public Wi-Fi pre-shared key from a captured handshake

    Why it's wrong here

    Capturing a WPA handshake requires physical proximity and active monitoring of the target's wireless network, which is intrusive and unrelated to collecting employee names. It also risks legal exposure and does not yield the identity data the tester seeks. This technique is not passive and does not address the stated goal of profiling employees from published sources.

  • ✗

    Performing a brute-force SMTP VRFY sweep against the target's mail gateway

    Why it's wrong here

    An SMTP VRFY sweep sends commands to the target's mail gateway, which is active reconnaissance that can be logged and may trigger alarms. Modern mail servers typically disable VRFY to prevent exactly this enumeration, so the technique is both intrusive and unreliable. It does not rely on published information, which the scenario explicitly requires.

  • ✓

    Reviewing the organization's LinkedIn company page and employee profiles

    Why this is correct

    LinkedIn profiles and company pages are published by the organization and its employees, so reviewing them is passive and directly yields names, titles, departments, and often the email naming convention. This aligns perfectly with the goal of building an employee profile from publicly available information without contacting target systems.

  • ✗

    Enumerating SMB shares on the target's internal file servers

    Why it's wrong here

    SMB enumeration requires network access to internal file servers and is an active technique that generates traffic on target infrastructure. It targets file shares rather than employee identity data, and it is outside the scope of an external, published-information-only exercise. It fails the passive requirement and does not directly produce names or email formats.

About these practice questions

Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.