CEH Wireless, IoT and Cloud Security Practice Question
Match each footprinting technique to its description.
Drag a concept onto its matching description — or click a concept then click the description.
Concepts
Matches
Query domain registration details
Gathering DNS records and subdomains
Using advanced search operators to find sensitive info
Manipulating people to reveal information
Search engine for internet-connected devices
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS interrogation: Extracting DNS records to discover network information
The correct matches are: DNS interrogation extracts DNS records, WHOIS lookup queries domain databases, Google hacking uses search operators, and social engineering manipulates people. Common confusions include swapping ping sweep (ICMP probing) with DNS interrogation or Google hacking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
✓
DNS interrogation: Extracting DNS records to discover network information
Why this is correct
DNS interrogation is a critical footprinting technique involving the querying of Domain Name System servers to extract various records. This process reveals crucial network infrastructure details, such as IP addresses (A records), mail servers (MX records), and authoritative name servers (NS records). Attackers use this information to map out an organization's network topology and identify potential targets for further exploitation.
✓
WHOIS lookup: Querying domain registration databases for contact and ownership details
Why this is correct
A WHOIS lookup involves querying publicly accessible databases that store registration information for domain names and IP addresses. This reconnaissance method provides valuable details including the domain registrar, registrant contact information, administrative and technical contacts, and domain expiration dates. Such data can help an attacker identify key personnel or gain insight into an organization's digital assets and their ownership.
✓
Google hacking: Using advanced search operators to find sensitive information
Why this is correct
Google hacking, also known as Google Dorking, leverages advanced search operators and specific keywords within search engines to uncover sensitive, publicly exposed information. Attackers use queries like `filetype:pdf confidential` or `intitle:index.of parent directory` to find login portals, configuration files, directory listings, or other data inadvertently left accessible on the web. This technique exploits misconfigurations rather than direct system vulnerabilities.
✓
Social engineering: Manipulating people to divulge confidential information
Why this is correct
Social engineering is a non-technical footprinting technique that relies on psychological manipulation to trick individuals into divulging confidential information or performing actions they wouldn't normally do. Attackers exploit human vulnerabilities such as trust, fear, or curiosity through methods like phishing, pretexting, or baiting. The goal is to obtain credentials, access codes, or internal network details without directly interacting with technical systems.
✗
Ping sweep: Using search operators to find sensitive information
Why it's wrong here
The description 'Using search operators to find sensitive information' incorrectly defines a ping sweep; this activity actually describes Google hacking or Dorking. A ping sweep is a network scanning technique used to identify active hosts on a network segment by sending Internet Control Message Protocol (ICMP) echo requests to a range of IP addresses. Its primary purpose is to determine which IP addresses are currently assigned to live devices, not to search for data.
✗
DNS interrogation: Identifying live hosts by sending ICMP requests
Why it's wrong here
The description 'Identifying live hosts by sending ICMP requests' is inaccurate for DNS interrogation; this action precisely defines a ping sweep. DNS interrogation, conversely, involves querying Domain Name System servers to extract records like A, MX, and NS, which reveal network topology and server details. It does not involve sending ICMP packets to discover active hosts, but rather passively gathers publicly available DNS data.
Courseiva writes every CEH question from scratch — 870 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.