Courseiva
Footprinting, Reconnaissance and ScanningeasyMultiple ChoiceObjective-mapped

CEH Footprinting, Reconnaissance and Scanning Practice Question

Which of the following tools is specifically designed to search the internet for exposed devices and services, such as industrial control systems and webcams, using banners and metadata?

⚠ Common exam trap

Candidates often confuse Shodan with a general-purpose search engine like Google or a network mapping tool like Nmap, failing to recognize that Shodan is purpose-built for indexing device banners and metadata from internet-connected systems.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Shodan

Shodan is a search engine specifically designed to scan the internet for exposed devices and services by collecting banners and metadata from protocols such as HTTP, SSH, FTP, and SNMP. Unlike general-purpose search engines, Shodan indexes device-specific information, making it ideal for discovering industrial control systems (ICS), webcams, and other IoT devices that respond to network probes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Maltego

    Why it's wrong here

    Maltego is a powerful open-source intelligence (OSINT) and graphical link analysis tool designed to visualize relationships between various entities such as individuals, domains, IP addresses, and documents. It aggregates data from diverse sources to construct a comprehensive graph, aiding analysts in uncovering hidden connections and patterns. However, Maltego does not actively scan or index internet-connected devices based on their service banners or open ports; its primary function is data correlation and visualization, not direct device discovery.

  • Nmap

    Why it's wrong here

    Nmap (Network Mapper) is a robust and versatile network scanning utility widely used for network discovery and security auditing within a defined network scope. It operates by sending raw packets to target hosts to identify active devices, open ports, running services, operating systems, and potential vulnerabilities. While Nmap can certainly identify devices and their services, it functions as an active scanner for specific targets or ranges, rather than maintaining a global, indexed database of internet-wide device banners like a specialized search engine.

  • Shodan

    Why this is correct

    Shodan functions as a specialized search engine that continuously scans the entire internet, indexing information derived from service banners, metadata, and open ports of various internet-connected devices. Unlike traditional web search engines, Shodan focuses on machine-readable data, enabling users to discover a vast array of devices, including industrial control systems, webcams, routers, and IoT devices, based on specific criteria like manufacturer, location, or exposed service. This unique capability makes it an indispensable tool for security researchers and penetration testers to identify vulnerable or misconfigured systems globally.

  • Google

    Why it's wrong here

    Google is a general-purpose web search engine primarily designed to index and retrieve information from websites, documents, and other content intended for human consumption. While it can sometimes indirectly lead to information about devices through publicly available documentation, news articles, or forum discussions, it does not actively scan for or index the service banners of internet-connected hardware. Its algorithms prioritize relevance for natural language queries, making it unsuitable for direct, programmatic discovery of device-specific technical details or vulnerabilities across the internet's device landscape.

About these practice questions

This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.