Courseiva

CEH · topic practice

Footprinting, Reconnaissance and Scanning practice questions

This CEH domain covers footprinting, reconnaissance, and scanning: gathering target intelligence through passive and active methods, then mapping live hosts, ports, services, and OS details. Questions test tool selection (Nmap, whois, nslookup, theHarvester, Shodan), scan-type behavior, evasion against IDS/IPS, and distinguishing passive from active collection in realistic analyst scenarios.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Footprinting, Reconnaissance and Scanning

What the exam tests

What to know about Footprinting, Reconnaissance and Scanning

Be able to pick the right reconnaissance or Nmap technique for a scenario and explain why it works. The single most important thing: know which methods touch the target directly (active) versus query public sources (passive), and how each Nmap flag changes detection risk.

Passive vs active reconnaissance: OSINT, whois, nslookup, Shodan, theHarvester versus direct target interaction

Nmap scan types and flags: -sS, -sT, -sU, -sV, -A, -O, -p, and their detection tradeoffs

Nmap evasion and spoofing: -sI idle scan, decoys, fragmentation, timing templates, and source-port manipulation

Service, port, and OS fingerprinting plus banner grabbing to enumerate versions and attack surface

Watch out for

Common Footprinting, Reconnaissance and Scanning exam traps

  • ▸Treating theHarvester, whois, and Shodan as active scanning when they query third-party or public sources without touching the target
  • ▸Assuming -sI idle scan works without a suitable idle zombie host that has predictable IP ID values and low traffic
  • ▸Confusing -sS half-open SYN scanning with -sT full connect, or expecting -A to evade IDS rather than trigger more traffic

Practice set

Footprinting, Reconnaissance and Scanning questions

20 questions · select your answer, then reveal the explanation

A penetration tester is attempting to evade an IDS/IPS while performing a port scan. They use the Nmap command: nmap -sS -f --data-length 20 -D RND:10 10.0.0.1. Which techniques are being employed to evade detection?

A security analyst observes unusual outbound traffic from an internal host to an external IP on port 443. The analyst suspects a reverse shell where the internal host initiates an HTTPS connection to the attacker. Which Nmap script would be MOST useful to confirm the nature of this traffic if the analyst can run a scan on the internal host?

A penetration tester runs `nmap -sS -sV -O -p- 192.168.1.10` and receives the following output snippet: 'PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 7.4 80/tcp open http Apache httpd 2.4.6 443/tcp open ssl/http Apache httpd 2.4.6'. Which THREE pieces of information can the tester derive from this output? (Choose 3)

A security analyst observes that an Nmap SYN scan against a target network returns all ports as 'filtered'. The analyst suspects an IDS/IPS is dropping inbound SYN packets. Which Nmap technique would MOST likely bypass this detection while still identifying open ports?

A security analyst runs the following Nmap command: nmap -sS -sV -O -p 22,80,443,3389 192.168.1.0/24. Which of the following BEST describes what this scan will accomplish?

Which TWO of the following are passive reconnaissance techniques? (Select 2)

During a security assessment, a tester uses Netcat to connect to a target's SMTP port and receive the service banner. Which command would achieve this?

A penetration tester is conducting reconnaissance and wants to identify live hosts in a range without being detected. Which TWO techniques would be MOST appropriate? (Choose two.)

Question 9easymultiple choice
Read the full DNS explanation →

A security analyst wants to discover all DNS records associated with a domain without triggering a full zone transfer. Which tool is BEST suited for this task?

A security analyst wants to perform banner grabbing on a web server without establishing a full TCP connection. Which tool would be MOST appropriate?

During a vulnerability assessment, which of the following tools is a comprehensive vulnerability scanner that uses a plugin architecture to detect thousands of vulnerabilities?

Which THREE of the following are valid Nmap NSE scripts that could be used for service version detection or vulnerability scanning? (Choose THREE.)

Question 13mediummultiple choice
Read the full DNS explanation →

An incident responder analyzes logs and finds repeated failed zone transfer attempts from an external IP. The zone transfer requests are targeting the domain example.com. Which DNS record type, if misconfigured, would allow this attack to succeed?

Which TWO of the following are examples of passive OS fingerprinting techniques? (Select 2)

Question 15mediummulti select
Read the full DNS explanation →

Which THREE of the following are valid methods to prevent DNS zone transfer attacks? (Select 3)

Which TWO of the following are examples of active reconnaissance? (Select 2)

A penetration tester is performing active reconnaissance against a web server and wants to identify the web server software, version, and enabled modules without triggering verbose error messages. The tester decides to use Nmap NSE scripts. Which TWO of the following NSE scripts are designed to gather HTTP server information? (Choose two.)

A security analyst runs the following Nmap command: nmap -sS -sV -O -p 22,80,443,3389 192.168.1.0/24. Which of the following BEST describes what this scan will accomplish?

During a passive reconnaissance phase, a penetration tester uses a tool to gather email addresses, subdomains, and employee names associated with a target domain without directly interacting with the target's systems. Which tool is BEST suited for this purpose?

A security analyst notices unusual outbound traffic from an internal server to a known malicious IP address on port 4444. The server is running a web application that was recently scanned using a vulnerability scanner. Which of the following is the MOST likely cause?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Footprinting, Reconnaissance and Scanning sessions

Start a Footprinting, Reconnaissance and Scanning only practice session

Every question in these sessions is drawn from the Footprinting, Reconnaissance and Scanning domain — nothing else.

Related practice questions

Related CEH topic practice pages

Move into related areas when this topic feels solid.

Scanning Networks and Enumeration practice questions

Scanning Networks and Enumeration practice questions for CEH.

Wireless, IoT and Cloud Security practice questions

Wireless, IoT and Cloud Security practice questions for CEH.

Vulnerability Analysis and System Hacking practice questions

Practise CEH questions linked to Vulnerability Analysis and System Hacking.

Advanced Topics: Wireless, Cloud, IoT, Cryptography practice questions

Sharpen your CEH knowledge of Advanced Topics: Wireless, Cloud, IoT, Cryptography.

Cryptography and Malware Analysis practice questions

Targeted CEH practice covering Cryptography and Malware Analysis.

Footprinting and Reconnaissance practice questions

Targeted CEH practice covering Footprinting and Reconnaissance.

Network and Web Application Attacks practice questions

Targeted CEH practice covering Network and Web Application Attacks.

Enumeration and System Hacking practice questions

Practise CEH questions linked to Enumeration and System Hacking.

Footprinting, Reconnaissance and Scanning practice questions

Sharpen your CEH knowledge of Footprinting, Reconnaissance and Scanning.

Social Engineering and Physical Security practice questions

Practise CEH questions linked to Social Engineering and Physical Security.

Malware, Social Engineering and Network Attacks practice questions

Sharpen your CEH knowledge of Malware, Social Engineering and Network Attacks.

Web Application and Injection Attacks practice questions

Sharpen your CEH knowledge of Web Application and Injection Attacks.

Frequently asked questions

What does the CEH exam test about Footprinting, Reconnaissance and Scanning?
Be able to pick the right reconnaissance or Nmap technique for a scenario and explain why it works. The single most important thing: know which methods touch the target directly (active) versus query public sources (passive), and how each Nmap flag changes detection risk.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Footprinting, Reconnaissance and Scanning questions in a focused session?
Yes — the session launcher on this page draws every question from the Footprinting, Reconnaissance and Scanning domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CEH topics?
Use the topic links above to move to related areas, or go back to the CEH question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CEH exam covers. They are not copied from any real exam or dump site.