Courseiva

CEH Footprinting, Reconnaissance and Scanning Practice Question

Which TWO of the following are common OSINT tools for passive reconnaissance? (Select 2)

⚠ Common exam trap

EC-Council often tests the distinction between passive and active reconnaissance, and the trap here is that candidates confuse tools like Nmap or hping3 (which are active) with passive OSINT tools because they are commonly used in the early stages of an engagement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

theHarvester

theHarvester (B) is a passive OSINT tool that gathers emails, subdomains, hosts, employee names, and open ports from public sources such as search engines, PGP key servers, and Shodan without directly touching the target. Maltego (D) is a graphical OSINT and link-analysis tool that queries public data sources and transforms to map relationships among people, domains, IPs, and organizations, making it a staple of passive reconnaissance. Metasploit (A) is an exploitation framework used for active attacks, not passive information gathering. hping3 (C) is a packet-crafting tool for active network probing and firewall testing. Nmap (E) performs active scanning by sending probes to targets, so it is not a passive OSINT tool.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Metasploit

    Why it's wrong here

    Metasploit is a powerful penetration testing framework primarily designed for developing, testing, and executing exploits against remote target systems. While it can be used in later stages of a penetration test, its core functionality revolves around vulnerability exploitation, payload delivery, and post-exploitation activities, rather than passive information gathering from public sources. Therefore, it is not considered a common OSINT tool.

  • ✓

    theHarvester

    Why this is correct

    theHarvester is a highly effective OSINT tool specifically designed for passive information gathering during the reconnaissance phase. It systematically collects publicly available data such as email addresses, subdomains, hostnames, employee names, and open ports from various public sources like search engines (Google, Bing), PGP key servers, LinkedIn, and Shodan. This makes it an excellent choice for building an initial profile of a target without direct interaction.

  • ✗

    hping3

    Why it's wrong here

    hping3 is a command-line oriented TCP/IP packet assembler/analyzer, primarily used for active network scanning, firewall testing, and port scanning. It constructs and sends custom packets to a target, eliciting responses that reveal network topology, firewall rules, and open ports. This direct interaction with the target system classifies it as an active reconnaissance tool, fundamentally distinct from passive OSINT methods.

  • ✓

    Maltego

    Why this is correct

    Maltego is a comprehensive OSINT and graphical link analysis tool that excels at collecting, analyzing, and visualizing relationships between disparate pieces of public information. It passively queries various data sources, known as "transforms," to uncover connections between people, organizations, domains, and other entities, presenting the findings in an intuitive, graph-based format. This capability makes it invaluable for understanding complex relationships without direct target interaction.

  • ✗

    Nmap

    Why it's wrong here

    Nmap (Network Mapper) is a renowned open-source utility for network discovery and security auditing. It actively sends specially crafted packets to target hosts and analyzes their responses to determine available hosts, services, operating systems, and firewall configurations. Because Nmap directly interacts with the target network to gather information, it is categorized as an active reconnaissance tool, which is distinct from passive OSINT techniques that avoid direct engagement.

About these practice questions

One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.