Courseiva

CEH · domain

Footprinting and Reconnaissance

Footprinting and Reconnaissance covers passive and active information gathering against a target before exploitation: DNS and WHOIS lookups, search-engine and social-media mining, website mirroring, email header and DSN analysis, and network range discovery. Questions present a scenario or command output and ask you to pick the most effective technique, identify footprinting tools, or infer conclusions from results.

15 questions4 easy6 medium5 hard

Focused practice

Practice Footprinting and Reconnaissance questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Footprinting and Reconnaissance

You must select the most effective reconnaissance technique for a scenario and read command output correctly. The key skill is distinguishing passive from active footprinting and knowing which tool or DNS query yields the needed information without touching the target directly.

Subdomain enumeration via DNS zone transfers, brute-forcing, and certificate transparency logs

WHOIS, nslookup, dig, and DNS record types (A, MX, NS, TXT, SOA)

Footprinting tool categories: search engines, email tracking, and website mirroring utilities

Email header analysis, DSN behavior, and information leaked by mail server responses

Watch out for

Common Footprinting and Reconnaissance exam traps

  • ▸Confusing active footprinting (direct queries to the target) with passive footprinting that only uses public third-party sources.
  • ▸Assuming a failed DNS zone transfer means no subdomains exist, when brute-forcing or certificate logs may still reveal them.
  • ▸Treating social engineering or scanning as footprinting; this domain stops at information gathering, not exploitation or enumeration of live services.

Question index

All Footprinting and Reconnaissance questions (15)

Click any question to see the full explanation, or start a practice session above.

1

An ethical hacker wants to discover subdomains of a target domain using only public information. Which of the following techniques is MOST effective?

Easy
2

Which TWO of the following are examples of passive footprinting techniques? (Select exactly 2.)

Medium
3

During the reconnaissance phase, a tester discovers that the target company's email server is configured to automatically respond to delivery status notifications (DSNs). Which type of attack could this information facilitate?

Medium
4

Which TWO of the following tools are specifically designed for footprinting and reconnaissance tasks? (Select two.)

Hard
5

Which THREE of the following are valid pieces of information that can be gathered from a properly configured Netcraft site report? (Select exactly 3.)

Hard
6

What can be inferred from the output?

Easy
7

Drag and drop the steps to set up a VPN using IPsec in tunnel mode into the correct order.

Medium
8

An ethical hacker is building a profile of a target organization's employees and wants to identify names, job titles, and email address formats using only information the organization has published. Which technique is BEST suited to this goal?

Easy
9

You are a penetration tester for a security firm. Your client, Acme Corp, has requested an external reconnaissance assessment. They have provided their primary domain 'acme.com'. You begin by performing passive footprinting using public sources. After gathering initial information, you want to identify their email servers, subdomains, and any exposed services. You also want to map their network infrastructure without directly interacting with their systems to avoid detection. Which course of action should you take next?

Medium
10

An ethical hacker runs the command shown in the exhibit. Which of the following conclusions can be drawn from the output?

Medium
11

During a penetration test, you discover that the target organization uses a cloud-based email service. Which technique would allow you to gather employee email addresses and potentially infer internal organizational structure?

Hard
12

Match each CEH phase to its key activity.

Medium
13

A security analyst is tasked with performing passive reconnaissance on a target organization. Which of the following is the BEST approach to gather information about the target's technology stack without directly interacting with the target's systems?

Hard
14

During an authorized external assessment, a tester wants to determine which mail exchangers and third-party SaaS providers a target uses without alerting the target's security team. The tester already knows the primary domain. Which single command best reveals the target's MX records using a public resolver while sending no traffic to the target itself?

Hard
15

Refer to the exhibit. An attacker runs the nslookup command shown. What information has been gathered?

Easy

Frequently asked questions

What does the Footprinting and Reconnaissance domain cover on the CEH exam?
You must select the most effective reconnaissance technique for a scenario and read command output correctly. The key skill is distinguishing passive from active footprinting and knowing which tool or DNS query yields the needed information without touching the target directly.
How many questions are in this domain?
This page lists all 15 Footprinting and Reconnaissance questions in the CEH question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Footprinting and Reconnaissance questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
ec-ceh EC-CEH footprinting recon Practice Questions