CEH Footprinting, Reconnaissance and Scanning Practice Question
Which TWO of the following are common OSINT tools for passive reconnaissance? (Select 2)
⚠ Common exam trap
EC-Council often tests the distinction between passive and active reconnaissance, and the trap here is that candidates confuse tools like Nmap or hping3 (which are active) with passive OSINT tools because they are commonly used in the early stages of an engagement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
theHarvester
theHarvester (B) is a passive OSINT tool that gathers emails, subdomains, hosts, employee names, and open ports from public sources such as search engines, PGP key servers, and Shodan without directly touching the target. Maltego (D) is a graphical OSINT and link-analysis tool that queries public data sources and transforms to map relationships among people, domains, IPs, and organizations, making it a staple of passive reconnaissance. Metasploit (A) is an exploitation framework used for active attacks, not passive information gathering. hping3 (C) is a packet-crafting tool for active network probing and firewall testing. Nmap (E) performs active scanning by sending probes to targets, so it is not a passive OSINT tool.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Metasploit
Why it's wrong here
Metasploit is a powerful penetration testing framework primarily designed for developing, testing, and executing exploits against remote target systems. While it can be used in later stages of a penetration test, its core functionality revolves around vulnerability exploitation, payload delivery, and post-exploitation activities, rather than passive information gathering from public sources. Therefore, it is not considered a common OSINT tool.
- ✓
theHarvester
Why this is correct
theHarvester is a highly effective OSINT tool specifically designed for passive information gathering during the reconnaissance phase. It systematically collects publicly available data such as email addresses, subdomains, hostnames, employee names, and open ports from various public sources like search engines (Google, Bing), PGP key servers, LinkedIn, and Shodan. This makes it an excellent choice for building an initial profile of a target without direct interaction.
- ✗
hping3
Why it's wrong here
hping3 is a command-line oriented TCP/IP packet assembler/analyzer, primarily used for active network scanning, firewall testing, and port scanning. It constructs and sends custom packets to a target, eliciting responses that reveal network topology, firewall rules, and open ports. This direct interaction with the target system classifies it as an active reconnaissance tool, fundamentally distinct from passive OSINT methods.
- ✓
Maltego
Why this is correct
Maltego is a comprehensive OSINT and graphical link analysis tool that excels at collecting, analyzing, and visualizing relationships between disparate pieces of public information. It passively queries various data sources, known as "transforms," to uncover connections between people, organizations, domains, and other entities, presenting the findings in an intuitive, graph-based format. This capability makes it invaluable for understanding complex relationships without direct target interaction.
- ✗
Nmap
Why it's wrong here
Nmap (Network Mapper) is a renowned open-source utility for network discovery and security auditing. It actively sends specially crafted packets to target hosts and analyzes their responses to determine available hosts, services, operating systems, and firewall configurations. Because Nmap directly interacts with the target network to gather information, it is categorized as an active reconnaissance tool, which is distinct from passive OSINT techniques that avoid direct engagement.
Go deeper
Related to this question
Learn chapter
Penetration Testing and Reporting
Key term
Active reconnaissance
Active reconnaissance is the process of directly interacting with a target system or network to gather information, often through scanning and probing.
Key term
Port Scanning Techniques
Port scanning techniques are methods used to probe a computer or network to discover which network ports are open and which services are running on those ports.
About these practice questions
One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.