CEH Footprinting, Reconnaissance and Scanning Practice Question
During a security assessment, a tester uses Maltego to gather information about a target organization. Which type of reconnaissance is being performed?
⚠ Common exam trap
EC-Council often tests the distinction between passive and active reconnaissance by presenting tools like Maltego or theHarvester as passive, while candidates mistakenly classify them as active due to the tool's interactive GUI or data aggregation features.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Passive reconnaissance
Maltego is a tool that collects publicly available information from sources like DNS records, WHOIS databases, and social media without directly interacting with the target's systems. This aligns with passive reconnaissance, which relies on open-source intelligence (OSINT) and does not send any packets to the target's network. The CEH defines passive reconnaissance as gathering information without engaging the target, making option A correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Passive reconnaissance
Why this is correct
This is correct because Maltego primarily functions as an Open Source Intelligence (OSINT) gathering tool. It aggregates publicly available information from various internet sources, such as DNS records, WHOIS databases, social media profiles, and search engines, without initiating any direct network connections or probes to the target's infrastructure. This method allows testers to build a comprehensive organizational footprint discreetly, minimizing the risk of detection by the target's security systems.
- ✗
Active reconnaissance
Why it's wrong here
Active reconnaissance involves direct interaction with the target's systems or network infrastructure, often through techniques like port scanning, ping sweeps, or banner grabbing. These actions send packets directly to the target, which can be logged or detected by intrusion detection systems (IDS) or firewalls. Maltego, by contrast, does not perform such direct network probes; it relies solely on querying third-party public data sources, thus avoiding direct engagement that could alert the target.
- ✗
Vulnerability scanning
Why it's wrong here
Vulnerability scanning is a distinct process that actively probes systems and applications to identify specific security weaknesses, misconfigurations, or known vulnerabilities. Tools like Nessus or OpenVAS send crafted packets and requests to analyze responses for potential exploits. Maltego, however, is designed for information gathering and relationship mapping, not for actively testing or identifying exploitable flaws within a target's systems. It collects data that might inform a vulnerability assessment but does not perform the assessment itself.
- ✗
Social engineering
Why it's wrong here
Social engineering relies on psychological manipulation to trick individuals into divulging confidential information or performing actions that compromise security. This technique inherently involves direct human interaction, whether through phishing emails, pretexting phone calls, or in-person deception. Maltego is an automated data aggregation tool that operates purely on publicly available data; it does not engage in any form of human interaction or psychological manipulation to achieve its objectives.
Visual reference
Go deeper
Related to this question
Learn chapter
Footprinting and Reconnaissance
Key term
Passive reconnaissance
Passive reconnaissance is the process of gathering information about a target system or network without directly interacting with it, using publicly available sources and stealthy observation.
Key term
Nmap Scanning
Nmap scanning is a method used to discover devices running on a network and find open ports, services, and security weaknesses.
About these practice questions
This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.