CEH Footprinting, Reconnaissance and Scanning Practice Question
Which THREE of the following are legitimate uses of the Shodan search engine in a security assessment? (Select 3)
⚠ Common exam trap
Many candidates confuse Shodan's passive banner-gathering capability with active exploitation or social engineering, leading them to select options that involve direct interaction with the target (SQL injection or phishing) instead of legitimate reconnaissance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Discovering internet-connected industrial control systems (ICS) with default passwords
Option B is correct because Shodan indexes internet-facing devices and exposes banners and metadata for ICS/SCADA systems (e.g., Modbus, Siemens, BACnet), allowing an assessor to identify exposed industrial control systems that may still use default credentials. Option C is correct because Shodan indexes SSL/TLS certificate data, including subject CN and SAN fields, so querying by certificate or domain reveals related subdomains and hostnames tied to a target's certificates. Option E is correct because Shodan continuously scans the internet and stores port/banner data, so an assessor can query an IP range (e.g., net:192.168.0.0/16) to enumerate open ports and running services without directly scanning the hosts. Option A is not a Shodan use because Shodan is a passive search engine for internet-connected device banners and does not perform active SQL injection attacks against web applications. Option D is not a Shodan use because Shodan does not send phishing emails; that is a social-engineering activity unrelated to its search/indexing capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Performing SQL injection on a web application
Why it's wrong here
Shodan is a passive reconnaissance tool that indexes banners and metadata from internet-connected devices, not an active exploitation platform. Performing SQL injection requires direct, interactive manipulation of a web application's input fields to exploit database vulnerabilities, a process fundamentally different from Shodan's passive data collection and search capabilities. Therefore, Shodan cannot be used to execute SQL injection attacks.
- ✓
Discovering internet-connected industrial control systems (ICS) with default passwords
Why this is correct
Shodan excels at identifying internet-facing industrial control systems (ICS) by indexing their unique banners, open ports, and service metadata, such as those associated with Modbus, Siemens S7, or Tridium Niagara protocols. While Shodan itself does not test for default passwords, its detailed service information often reveals specific device models, firmware versions, or web interfaces. This context allows security researchers to infer or attempt commonly known default credentials, facilitating the discovery of vulnerable ICS devices.
- ✓
Mapping all SSL/TLS certificates for a domain to find subdomains
Why this is correct
Shodan actively collects and indexes SSL/TLS certificate data from internet-connected services. These certificates frequently contain a Common Name (CN) and multiple Subject Alternative Names (SANs) that list not only the primary domain but also associated subdomains (e.g., `www.example.com`, `api.example.com`). By querying Shodan for certificates issued to a specific domain, security professionals can passively enumerate a comprehensive list of its subdomains, significantly aiding in the reconnaissance phase of security assessments.
- ✗
Sending phishing emails to employees of a target organization
Why it's wrong here
Shodan is a network search engine focused on indexing information about internet-connected devices and services, not a platform for social engineering or direct communication. Sending phishing emails to employees requires access to email addresses and the capability to craft and deliver malicious messages, which are functionalities entirely outside of Shodan's scope. Shodan does not collect individual user data or possess email sending capabilities necessary for launching phishing campaigns.
- ✓
Identifying open ports and services on all hosts in a given IP range
Why this is correct
Shodan continuously scans the entire IPv4 space and portions of IPv6, collecting banner information, service versions, and associated metadata from open ports on discovered hosts. Users can leverage Shodan's powerful query language to specify IP ranges (e.g., `net:192.168.1.0/24`) or organizations. The platform then returns a detailed inventory of all indexed hosts within that range, comprehensively listing their open ports, running services, and often even identifying potential vulnerabilities based on the collected banner data.
Go deeper
Related to this question
About these practice questions
This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.