Courseiva

CEH Footprinting, Reconnaissance and Scanning Practice Question

Which THREE of the following are valid DNS record types that an attacker might query during reconnaissance to gather information about a target domain? (Select 3)

⚠ Common exam trap

EC-Council often tests the distinction between DNS record types and application-layer protocols, so candidates mistakenly select FTP or HTTP because they are common network services, but they are not valid DNS resource records.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A (IPv4 address)

Option B (A record) is correct because an A record maps a hostname to its IPv4 address, so querying it during reconnaissance reveals the IP addresses of the target's web, mail, or other hosts for further scanning. Option C (NS record) is correct because NS records identify the authoritative name servers for the domain, letting an attacker map the DNS infrastructure and potentially attempt zone transfers or subdomain enumeration. Option E (MX record) is correct because MX records list the mail exchange servers handling email for the domain, exposing mail infrastructure, third-party providers, and additional hostnames to investigate. Options A (FTP) and D (HTTP) are not DNS record types at all; they are application-layer protocols, and no DNS query returns an 'FTP' or 'HTTP' record, so they do not belong among valid DNS reconnaissance record types.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    FTP (file transfer)

    Why it's wrong here

    FTP (File Transfer Protocol) is an application-layer protocol used for transferring files between a client and server on a computer network. It defines the rules for data exchange, authentication, and session management, operating over TCP ports 20 and 21. DNS records, conversely, are database entries that map domain names to various types of information, such as IP addresses or mail servers, facilitating name resolution rather than direct service provision. Therefore, FTP itself is not a valid DNS record type.

  • ✓

    A (IPv4 address)

    Why this is correct

    An 'A' record, short for Address record, is a fundamental DNS record type that maps a domain name or hostname to its corresponding IPv4 address. When a user attempts to access a website, the DNS resolver queries for the 'A' record to translate the human-readable domain into the numerical IP address required for network communication. This record is essential for directing traffic to the correct server hosting the website or service.

  • ✓

    NS (name server)

    Why this is correct

    An 'NS' record, or Name Server record, specifies the authoritative DNS servers for a particular domain or subdomain. These records delegate authority to other DNS servers, indicating which servers are responsible for providing definitive answers about the domain's records. During a DNS query, NS records guide resolvers to the correct servers, and they are particularly relevant for attackers attempting zone transfers to enumerate all records within a domain.

  • ✗

    HTTP (hypertext transfer)

    Why it's wrong here

    HTTP (Hypertext Transfer Protocol) is an application-layer protocol used for transmitting hypermedia documents, such as HTML, across the internet. It defines how messages are formatted and transmitted, and what actions web servers and browsers should take in response to various commands. Unlike DNS records, which provide static mapping information for name resolution, HTTP is a communication protocol that operates *after* DNS has resolved a domain name to an IP address.

  • ✓

    MX (mail exchange)

    Why this is correct

    An 'MX' record, or Mail Exchange record, specifies the mail servers responsible for accepting email messages on behalf of a domain and their preference values. When an email is sent, the sending mail server queries DNS for the recipient's domain's MX records to determine where to deliver the message. These records are critical for proper email routing and can be enumerated by attackers to identify potential targets for email-related attacks or to gather information about an organization's mail infrastructure.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.