Courseiva

CEH · domain

Footprinting and Reconnaissance

Practise Certified Ethical Hacker CEH Footprinting and Reconnaissance practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

14 questions3 easy6 medium5 hard

Focused practice

Practice Footprinting and Reconnaissance questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Footprinting and Reconnaissance

Footprinting and Reconnaissance questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Footprinting and Reconnaissance exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Footprinting and Reconnaissance questions (14)

Click any question to see the full explanation, or start a practice session above.

1

An ethical hacker wants to discover subdomains of a target domain using only public information. Which of the following techniques is MOST effective?

Easy
2

Which TWO of the following are examples of passive footprinting techniques? (Select exactly 2.)

Medium
3

During the reconnaissance phase, a tester discovers that the target company's email server is configured to automatically respond to delivery status notifications (DSNs). Which type of attack could this information facilitate?

Medium
4

Which TWO of the following tools are specifically designed for footprinting and reconnaissance tasks? (Select two.)

Hard
5

You are a penetration tester hired to perform a security assessment for a medium-sized e-commerce company, "ShopSmart". The company hosts its website on a shared hosting environment and uses a third-party payment gateway. Your goal is to gather as much information as possible without triggering any alarms. During the initial footprinting, you discover that the company's domain "shopsmart.com" was registered five years ago and the WHOIS record shows the registrant's name, address, phone number, and email. The email address is "admin@shopsmart.com". You also find a job posting on LinkedIn that mentions they are looking for a "Senior PHP Developer with experience in Laravel and MySQL". Additionally, by using the Wayback Machine, you find an old version of the site that includes a comment in the HTML source: "<!-- TODO: Remove debug page before launch: /dev/test.php -->". You attempt to access /dev/test.php but receive a 404 error. What should you do NEXT to maximize information gain while remaining passive?

Hard
6

Which THREE of the following are valid pieces of information that can be gathered from a properly configured Netcraft site report? (Select exactly 3.)

Hard
7

What can be inferred from the output?

Easy
8

Drag and drop the steps to set up a VPN using IPsec in tunnel mode into the correct order.

Medium
9

You are a penetration tester for a security firm. Your client, Acme Corp, has requested an external reconnaissance assessment. They have provided their primary domain 'acme.com'. You begin by performing passive footprinting using public sources. After gathering initial information, you want to identify their email servers, subdomains, and any exposed services. You also want to map their network infrastructure without directly interacting with their systems to avoid detection. Which course of action should you take next?

Medium
10

An ethical hacker runs the command shown in the exhibit. Which of the following conclusions can be drawn from the output?

Medium
11

During a penetration test, you discover that the target organization uses a cloud-based email service. Which technique would allow you to gather employee email addresses and potentially infer internal organizational structure?

Hard
12

Match each CEH phase to its key activity.

Medium
13

A security analyst is tasked with performing passive reconnaissance on a target organization. Which of the following is the BEST approach to gather information about the target's technology stack without directly interacting with the target's systems?

Hard
14

Refer to the exhibit. An attacker runs the nslookup command shown. What information has been gathered?

Easy

Frequently asked questions

What does the Footprinting and Reconnaissance domain cover on the CEH exam?
Footprinting and Reconnaissance questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 14 Footprinting and Reconnaissance questions in the CEH question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Footprinting and Reconnaissance questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
ec-ceh EC-CEH footprinting recon Practice Questions