CEH Footprinting, Reconnaissance and Scanning Practice Question
Which of the following tools is specifically designed to perform Google dorking and automate searching for vulnerable web applications and sensitive information?
⚠ Common exam trap
A common mix-up: candidates confuse general OSINT tools like theHarvester or Maltego with Google-dorking-specific automation, failing to recognize that Googledork is the only option explicitly built for executing and automating Google dork queries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Googledork
Googledork (also known as Google Dork) is a tool specifically designed to automate Google dorking queries, which use advanced search operators to find vulnerable web applications and sensitive information exposed in search results. It systematically executes predefined dork queries against Google's index to identify SQL injection points, exposed configuration files, login pages, and other security weaknesses, making it the correct choice for this task.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Maltego
Why it's wrong here
Maltego is a powerful open-source intelligence (OSINT) and graphical link analysis tool designed to gather, analyze, and visualize connections between disparate pieces of information, such as domains, IP addresses, people, and organizations. It utilizes "transforms" to query various data sources and map relationships, but it does not specifically automate the construction or execution of advanced Google search queries (dorks) to directly uncover web-based vulnerabilities or sensitive data indexed by search engines. Its primary strength lies in relationship mapping, not targeted search engine exploitation.
- ✗
theHarvester
Why it's wrong here
theHarvester is an effective open-source intelligence (OSINT) tool primarily focused on gathering public information like email addresses, subdomains, hostnames, and employee names from various public sources, including search engines, PGP key servers, and Shodan. While it leverages search engines as a data source, its methodology involves extracting specific data types from general search results rather than systematically generating and executing complex Google dorks to identify misconfigurations or exposed data through targeted search engine queries. It's designed for data collection, not dork automation.
- ✓
Googledork
Why this is correct
Googledork is a specialized utility explicitly engineered to automate the process of Google Hacking, commonly known as Google Dorking. This tool systematically generates and executes advanced search queries (dorks) against the Google search engine, leveraging specific operators like site:, filetype:, intitle:, and inurl: to discover exposed sensitive files, misconfigured servers, login pages, and other vulnerable information indexed by Google. Its core function is to streamline the identification of security weaknesses through targeted search engine exploitation, making it the correct answer.
- ✗
Shodan
Why it's wrong here
Shodan functions as a unique search engine specifically designed to discover and categorize internet-connected devices, services, and industrial control systems (ICS) based on their banners, open ports, and metadata. Unlike Google, which primarily indexes web content, Shodan actively scans the internet to index device information. While it is invaluable for reconnaissance to find vulnerable devices and services, its search methodology and target scope are fundamentally different from Google dorking, which exploits Google's web indexing capabilities to find web-based vulnerabilities and data.
Go deeper
Related to this question
About these practice questions
This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.