CEH · domain
Footprinting and Reconnaissance
Practise Certified Ethical Hacker CEH Footprinting and Reconnaissance practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Footprinting and Reconnaissance questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Footprinting and Reconnaissance
Footprinting and Reconnaissance questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Footprinting and Reconnaissance exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Footprinting and Reconnaissance questions (14)
Click any question to see the full explanation, or start a practice session above.
An ethical hacker wants to discover subdomains of a target domain using only public information. Which of the following techniques is MOST effective?
Easy2Which TWO of the following are examples of passive footprinting techniques? (Select exactly 2.)
Medium3During the reconnaissance phase, a tester discovers that the target company's email server is configured to automatically respond to delivery status notifications (DSNs). Which type of attack could this information facilitate?
Medium4Which TWO of the following tools are specifically designed for footprinting and reconnaissance tasks? (Select two.)
Hard5You are a penetration tester hired to perform a security assessment for a medium-sized e-commerce company, "ShopSmart". The company hosts its website on a shared hosting environment and uses a third-party payment gateway. Your goal is to gather as much information as possible without triggering any alarms. During the initial footprinting, you discover that the company's domain "shopsmart.com" was registered five years ago and the WHOIS record shows the registrant's name, address, phone number, and email. The email address is "admin@shopsmart.com". You also find a job posting on LinkedIn that mentions they are looking for a "Senior PHP Developer with experience in Laravel and MySQL". Additionally, by using the Wayback Machine, you find an old version of the site that includes a comment in the HTML source: "<!-- TODO: Remove debug page before launch: /dev/test.php -->". You attempt to access /dev/test.php but receive a 404 error. What should you do NEXT to maximize information gain while remaining passive?
Hard6Which THREE of the following are valid pieces of information that can be gathered from a properly configured Netcraft site report? (Select exactly 3.)
Hard7What can be inferred from the output?
Easy8Drag and drop the steps to set up a VPN using IPsec in tunnel mode into the correct order.
Medium9You are a penetration tester for a security firm. Your client, Acme Corp, has requested an external reconnaissance assessment. They have provided their primary domain 'acme.com'. You begin by performing passive footprinting using public sources. After gathering initial information, you want to identify their email servers, subdomains, and any exposed services. You also want to map their network infrastructure without directly interacting with their systems to avoid detection. Which course of action should you take next?
Medium10An ethical hacker runs the command shown in the exhibit. Which of the following conclusions can be drawn from the output?
Medium11During a penetration test, you discover that the target organization uses a cloud-based email service. Which technique would allow you to gather employee email addresses and potentially infer internal organizational structure?
Hard12Match each CEH phase to its key activity.
Medium13A security analyst is tasked with performing passive reconnaissance on a target organization. Which of the following is the BEST approach to gather information about the target's technology stack without directly interacting with the target's systems?
Hard14Refer to the exhibit. An attacker runs the nslookup command shown. What information has been gathered?
EasyOther domains
All CEH exam domains
Frequently asked questions
- What does the Footprinting and Reconnaissance domain cover on the CEH exam?
- Footprinting and Reconnaissance questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 14 Footprinting and Reconnaissance questions in the CEH question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Footprinting and Reconnaissance questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.