Courseiva

CEH Footprinting, Reconnaissance and Scanning Practice Question

Which THREE of the following are legitimate uses of the Shodan search engine in a security assessment? (Select 3)

⚠ Common exam trap

Many candidates confuse Shodan's passive banner-gathering capability with active exploitation or social engineering, leading them to select options that involve direct interaction with the target (SQL injection or phishing) instead of legitimate reconnaissance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Discovering internet-connected industrial control systems (ICS) with default passwords

Option B is correct because Shodan indexes internet-facing devices and exposes banners and metadata for ICS/SCADA systems (e.g., Modbus, Siemens, BACnet), allowing an assessor to identify exposed industrial control systems that may still use default credentials. Option C is correct because Shodan indexes SSL/TLS certificate data, including subject CN and SAN fields, so querying by certificate or domain reveals related subdomains and hostnames tied to a target's certificates. Option E is correct because Shodan continuously scans the internet and stores port/banner data, so an assessor can query an IP range (e.g., net:192.168.0.0/16) to enumerate open ports and running services without directly scanning the hosts. Option A is not a Shodan use because Shodan is a passive search engine for internet-connected device banners and does not perform active SQL injection attacks against web applications. Option D is not a Shodan use because Shodan does not send phishing emails; that is a social-engineering activity unrelated to its search/indexing capabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Performing SQL injection on a web application

    Why it's wrong here

    Shodan is a passive reconnaissance tool that indexes banners and metadata from internet-connected devices, not an active exploitation platform. Performing SQL injection requires direct, interactive manipulation of a web application's input fields to exploit database vulnerabilities, a process fundamentally different from Shodan's passive data collection and search capabilities. Therefore, Shodan cannot be used to execute SQL injection attacks.

  • ✓

    Discovering internet-connected industrial control systems (ICS) with default passwords

    Why this is correct

    Shodan excels at identifying internet-facing industrial control systems (ICS) by indexing their unique banners, open ports, and service metadata, such as those associated with Modbus, Siemens S7, or Tridium Niagara protocols. While Shodan itself does not test for default passwords, its detailed service information often reveals specific device models, firmware versions, or web interfaces. This context allows security researchers to infer or attempt commonly known default credentials, facilitating the discovery of vulnerable ICS devices.

  • ✓

    Mapping all SSL/TLS certificates for a domain to find subdomains

    Why this is correct

    Shodan actively collects and indexes SSL/TLS certificate data from internet-connected services. These certificates frequently contain a Common Name (CN) and multiple Subject Alternative Names (SANs) that list not only the primary domain but also associated subdomains (e.g., `www.example.com`, `api.example.com`). By querying Shodan for certificates issued to a specific domain, security professionals can passively enumerate a comprehensive list of its subdomains, significantly aiding in the reconnaissance phase of security assessments.

  • ✗

    Sending phishing emails to employees of a target organization

    Why it's wrong here

    Shodan is a network search engine focused on indexing information about internet-connected devices and services, not a platform for social engineering or direct communication. Sending phishing emails to employees requires access to email addresses and the capability to craft and deliver malicious messages, which are functionalities entirely outside of Shodan's scope. Shodan does not collect individual user data or possess email sending capabilities necessary for launching phishing campaigns.

  • ✓

    Identifying open ports and services on all hosts in a given IP range

    Why this is correct

    Shodan continuously scans the entire IPv4 space and portions of IPv6, collecting banner information, service versions, and associated metadata from open ports on discovered hosts. Users can leverage Shodan's powerful query language to specify IP ranges (e.g., `net:192.168.1.0/24`) or organizations. The platform then returns a detailed inventory of all indexed hosts within that range, comprehensively listing their open ports, running services, and often even identifying potential vulnerabilities based on the collected banner data.

About these practice questions

This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.