Courseiva

CEH · topic practice

Footprinting, Reconnaissance and Scanning practice questions

Practise Certified Ethical Hacker CEH Footprinting, Reconnaissance and Scanning practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Footprinting, Reconnaissance and Scanning

What the exam tests

What to know about Footprinting, Reconnaissance and Scanning

Footprinting, Reconnaissance and Scanning questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Footprinting, Reconnaissance and Scanning exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Footprinting, Reconnaissance and Scanning questions

20 questions · select your answer, then reveal the explanation

A penetration tester is attempting to evade an IDS/IPS while performing a port scan. They use the Nmap command: nmap -sS -f --data-length 20 -D RND:10 10.0.0.1. Which techniques are being employed to evade detection?

Question 2hardmulti select
Read the full DNS explanation →

Which THREE of the following are valid DNS record types that an attacker might query during reconnaissance to gather information about a target domain? (Select 3)

A security analyst observes unusual outbound traffic from an internal host to an external IP on port 443. The analyst suspects a reverse shell where the internal host initiates an HTTPS connection to the attacker. Which Nmap script would be MOST useful to confirm the nature of this traffic if the analyst can run a scan on the internal host?

A penetration tester runs `nmap -sS -sV -O -p- 192.168.1.10` and receives the following output snippet: 'PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 7.4 80/tcp open http Apache httpd 2.4.6 443/tcp open ssl/http Apache httpd 2.4.6'. Which THREE pieces of information can the tester derive from this output? (Choose 3)

Which TWO of the following are valid port states that Nmap can report? (Select 2)

During a security assessment, a tester uses Netcat to connect to a target's SMTP port and receive the service banner. Which command would achieve this?

A penetration tester is conducting reconnaissance and wants to identify live hosts in a range without being detected. Which TWO techniques would be MOST appropriate? (Choose two.)

A security analyst wants to perform banner grabbing on a web server without establishing a full TCP connection. Which tool would be MOST appropriate?

Question 9hardmulti select
Read the full DNS explanation →

Which THREE of the following are common countermeasures to prevent DNS zone transfers from being abused? (Choose THREE.)

Which THREE of the following are valid Nmap NSE scripts that could be used for service version detection or vulnerability scanning? (Choose THREE.)

Which TWO of the following are examples of passive OS fingerprinting techniques? (Select 2)

Which TWO of the following are common OSINT tools for passive reconnaissance? (Select 2)

Question 13mediummulti select
Read the full DNS explanation →

Which THREE of the following are valid methods to prevent DNS zone transfer attacks? (Select 3)

Which THREE of the following are legitimate uses of the Shodan search engine in a security assessment? (Select 3)

Which TWO OSINT tools are commonly used to gather email addresses and subdomains associated with a target domain? (Select 2)

A security analyst runs the following Nmap command: nmap -sS -sV -O -p 22,80,443,3389 192.168.1.0/24. Which of the following BEST describes what this scan will accomplish?

During a passive reconnaissance phase, a penetration tester uses a tool to gather email addresses, subdomains, and employee names associated with a target domain without directly interacting with the target's systems. Which tool is BEST suited for this purpose?

A security analyst notices unusual outbound traffic from an internal server to a known malicious IP address on port 4444. The server is running a web application that was recently scanned using a vulnerability scanner. Which of the following is the MOST likely cause?

Question 19hardmultiple choice
Read the full DNS explanation →

During a penetration test, you execute the following command: dnsrecon -d example.com -t axfr. The output shows 'AXFR record received' followed by a list of all DNS records. What does this indicate about the target's DNS configuration?

Which Google dork would a penetration tester use to find login pages of websites that have 'admin' in the URL?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Footprinting, Reconnaissance and Scanning sessions

Start a Footprinting, Reconnaissance and Scanning only practice session

Every question in these sessions is drawn from the Footprinting, Reconnaissance and Scanning domain — nothing else.

Related practice questions

Related CEH topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CEH exam test about Footprinting, Reconnaissance and Scanning?
Footprinting, Reconnaissance and Scanning questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Footprinting, Reconnaissance and Scanning questions in a focused session?
Yes — the session launcher on this page draws every question from the Footprinting, Reconnaissance and Scanning domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CEH topics?
Use the topic links above to move to related areas, or go back to the CEH question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CEH exam covers. They are not copied from any real exam or dump site.