Courseiva
Footprinting and ReconnaissancemediumMatchingObjective-mapped

CEH Footprinting and Reconnaissance Practice Question

Match each CEH phase to its key activity.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Gathering information about the target

Identifying live hosts, open ports, and services

Exploiting vulnerabilities to enter the system

Installing backdoors for persistent access

Clearing logs and hiding evidence

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Reconnaissance: Passive information gathering

The five phases of ethical hacking (as per EC-Council) are Reconnaissance, Scanning & Enumeration, Gaining Access, Maintaining Access, and Clearing Tracks. In this set, options A-D correctly match phases to their key activities, while options E and F are distractors with swapped definitions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Reconnaissance: Passive information gathering

    Why this is correct

    Reconnaissance, specifically passive information gathering, involves collecting data about a target without directly engaging their systems or networks. This often utilizes Open Source Intelligence (OSINT) techniques, such as querying public databases, social media, or search engines, to map out the target's infrastructure, personnel, and potential vulnerabilities from a distance. The goal is to build a comprehensive profile without triggering any alerts.

  • Scanning: Active probing for vulnerabilities

    Why this is correct

    Scanning represents the active phase where an attacker directly interacts with the target network to identify live hosts, open ports, and running services. Tools like Nmap are employed for port scanning, while vulnerability scanners such as Nessus or OpenVAS are used to detect known security weaknesses and misconfigurations on identified systems. This phase provides a detailed technical blueprint for subsequent exploitation attempts.

  • Gaining Access: Exploiting vulnerabilities to gain entry

    Why this is correct

    Gaining Access is the critical phase where identified vulnerabilities are actively exploited to breach the target's security perimeter. This involves leveraging specific exploits against discovered weaknesses, such as unpatched software, misconfigured services, or weak credentials, to establish an initial foothold. The objective is to execute malicious code, obtain a shell, or achieve unauthorized control over a system or network resource.

  • Maintaining Access: Ensuring persistent access

    Why this is correct

    Maintaining Access focuses on establishing persistent control over compromised systems to ensure future re-entry, even if initial vulnerabilities are patched. This often involves deploying backdoors, rootkits, or creating new user accounts with elevated privileges, along with modifying system configurations or scheduling tasks. The aim is to retain a covert presence and continue operations without needing to re-exploit the original vulnerability.

  • Reconnaissance: Active scanning of target network

    Why it's wrong here

    This option is incorrect because "active scanning of target network" describes the Scanning phase, not Reconnaissance. Reconnaissance primarily involves passive information gathering, such as OSINT, without direct interaction that could alert the target. Active scanning, by contrast, sends packets directly to the target's systems, which is characteristic of the more intrusive Scanning phase.

  • Clearing Tracks: Gaining initial access

    Why it's wrong here

    This option is incorrect because "Gaining initial access" is a distinct phase focused on exploiting vulnerabilities to enter a system. Clearing Tracks, conversely, is a post-exploitation activity performed *after* access has been gained and objectives achieved. Its purpose is to remove forensic evidence, such as log entries, command history, and temporary files, to hinder detection and attribution.

About these practice questions

This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.