Courseiva
Wireless, IoT and Cloud SecuritymediumMatchingObjective-mapped

CEH Wireless, IoT and Cloud Security Practice Question

Match each footprinting technique to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Query domain registration details

Gathering DNS records and subdomains

Using advanced search operators to find sensitive info

Manipulating people to reveal information

Search engine for internet-connected devices

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

DNS interrogation: Extracting DNS records to discover network information

The correct matches are: DNS interrogation extracts DNS records, WHOIS lookup queries domain databases, Google hacking uses search operators, and social engineering manipulates people. Common confusions include swapping ping sweep (ICMP probing) with DNS interrogation or Google hacking.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • DNS interrogation: Extracting DNS records to discover network information

    Why this is correct

    DNS interrogation is a critical footprinting technique involving the querying of Domain Name System servers to extract various records. This process reveals crucial network infrastructure details, such as IP addresses (A records), mail servers (MX records), and authoritative name servers (NS records). Attackers use this information to map out an organization's network topology and identify potential targets for further exploitation.

  • WHOIS lookup: Querying domain registration databases for contact and ownership details

    Why this is correct

    A WHOIS lookup involves querying publicly accessible databases that store registration information for domain names and IP addresses. This reconnaissance method provides valuable details including the domain registrar, registrant contact information, administrative and technical contacts, and domain expiration dates. Such data can help an attacker identify key personnel or gain insight into an organization's digital assets and their ownership.

  • Google hacking: Using advanced search operators to find sensitive information

    Why this is correct

    Google hacking, also known as Google Dorking, leverages advanced search operators and specific keywords within search engines to uncover sensitive, publicly exposed information. Attackers use queries like `filetype:pdf confidential` or `intitle:index.of parent directory` to find login portals, configuration files, directory listings, or other data inadvertently left accessible on the web. This technique exploits misconfigurations rather than direct system vulnerabilities.

  • Social engineering: Manipulating people to divulge confidential information

    Why this is correct

    Social engineering is a non-technical footprinting technique that relies on psychological manipulation to trick individuals into divulging confidential information or performing actions they wouldn't normally do. Attackers exploit human vulnerabilities such as trust, fear, or curiosity through methods like phishing, pretexting, or baiting. The goal is to obtain credentials, access codes, or internal network details without directly interacting with technical systems.

  • Ping sweep: Using search operators to find sensitive information

    Why it's wrong here

    The description 'Using search operators to find sensitive information' incorrectly defines a ping sweep; this activity actually describes Google hacking or Dorking. A ping sweep is a network scanning technique used to identify active hosts on a network segment by sending Internet Control Message Protocol (ICMP) echo requests to a range of IP addresses. Its primary purpose is to determine which IP addresses are currently assigned to live devices, not to search for data.

  • DNS interrogation: Identifying live hosts by sending ICMP requests

    Why it's wrong here

    The description 'Identifying live hosts by sending ICMP requests' is inaccurate for DNS interrogation; this action precisely defines a ping sweep. DNS interrogation, conversely, involves querying Domain Name System servers to extract records like A, MX, and NS, which reveal network topology and server details. It does not involve sending ICMP packets to discover active hosts, but rather passively gathers publicly available DNS data.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CEH question from scratch — 870 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.