CEH Footprinting, Reconnaissance and Scanning Practice Question
Which TWO OSINT tools are commonly used to gather email addresses and subdomains associated with a target domain? (Select 2)
⚠ Common exam trap
A common mix-up: candidates confuse Shodan as an OSINT tool for email/subdomain gathering because it is a well-known reconnaissance resource, but Shodan specifically indexes internet-facing devices and services, not domain-associated emails or subdomains.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
theHarvester
theHarvester (C) is correct because it is a dedicated OSINT reconnaissance tool that queries public sources such as search engines, PGP key servers, and certificate transparency logs to harvest email addresses, employee names, hosts, and subdomains for a target domain. Maltego (D) is also correct because it is a graphical link-analysis and OSINT platform whose transforms aggregate data from DNS records, WHOIS, certificate transparency, and other public sources to map domains, subdomains, and associated email addresses. Nmap (A) is a port scanner and host-discovery tool, not an email/subdomain OSINT collector, so it does not fit. Nessus (B) is a vulnerability scanner that assesses hosts for weaknesses rather than enumerating emails and subdomains. Shodan (E) is an internet-connected-device search engine that indexes exposed services and banners, not a tool primarily used to harvest email addresses and subdomains for a domain.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Nmap
Why it's wrong here
Nmap (Network Mapper) is an open-source utility primarily used for network discovery and security auditing. It actively sends packets to target hosts and analyzes their responses to identify open ports, running services, operating systems, and potential vulnerabilities. Its methodology involves direct network interaction, making it an active scanning tool rather than a passive OSINT tool designed for scraping public sources for email addresses.
- ✗
Nessus
Why it's wrong here
Nessus is a widely recognized, proprietary vulnerability scanner developed by Tenable. It performs comprehensive security assessments by actively probing target systems and networks for known vulnerabilities, misconfigurations, and missing patches. This active, intrusive scanning process involves direct interaction with the target environment to identify security flaws, which is fundamentally different from the passive collection of email addresses from publicly available information sources.
- ✓
theHarvester
Why this is correct
theHarvester is a specialized, open-source OSINT tool designed for gathering publicly available information, including email addresses, subdomains, hostnames, and employee names. It passively queries various public data sources such as search engines (e.g., Google, Bing), PGP key servers, LinkedIn, and Shodan to collect intelligence. This makes it exceptionally effective for the initial reconnaissance phase of a penetration test or security assessment, providing valuable contact and infrastructure information.
- ✓
Maltego
Why this is correct
Maltego is a powerful graphical link analysis tool used for data mining and visualizing relationships between disparate pieces of information. It leverages "transforms" to query numerous public data sources, including DNS records, social media platforms, WHOIS databases, and search engines, to discover entities like email addresses, phone numbers, domains, and their interconnections. Maltego's strength lies in its ability to present complex OSINT findings in an intuitive, visual graph format, aiding in comprehensive intelligence gathering.
- ✗
Shodan
Why it's wrong here
Shodan is a unique search engine specifically designed to discover internet-connected devices and services, often referred to as the "search engine for the Internet of Things." It indexes banners and metadata from various network services (e.g., HTTP, FTP, SSH) across the globe, allowing users to find specific device types, open ports, and geographic locations. While it can reveal exposed services, its primary function is not to passively scrape public websites or databases for email addresses or subdomains in the manner of dedicated OSINT tools.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.