Courseiva

CEH Footprinting, Reconnaissance and Scanning Practice Question

While performing reconnaissance, a tester uses a Google dork to find login pages exposed on the internet. Which of the following is an example of a Google dork that could be used for this purpose?

⚠ Common exam trap

EC-Council often tests the distinction between operators that search URL content ('inurl:') versus page content ('intitle:') or file types ('filetype:'), leading candidates to confuse 'filetype:pdf' as a valid dork for finding login pages when it actually targets document files.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

inurl:login.php

The Google dork 'inurl:login.php' instructs Google to return only URLs that contain the string 'login.php' in the URL path. This is a classic reconnaissance technique to discover exposed login pages, as many web applications use 'login.php' as the default authentication endpoint. The 'inurl:' operator filters search results based on the literal text in the URL, making it ideal for footprinting specific web resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    inurl:login.php

    Why this is correct

    The `inurl:` operator restricts results to URLs containing the specified string, so `inurl:login.php` surfaces pages whose addresses include "login.php" — directly satisfying the stem's requirement to find exposed login pages. It targets URL structure rather than page content, making it precise for locating authentication endpoints during reconnaissance.

  • ✗

    site:example.com -www

    Why it's wrong here

    site:example.com -www enumerates indexed pages on a domain while excluding the www host, useful for mapping subdomains and non-standard hosts. It does not filter for authentication interfaces, so results include every indexed page; locating login portals needs inurl: or intitle: operators targeting sign-in paths.

  • ✗

    filetype:pdf

    Why it's wrong here

    filetype:pdf restricts results to PDF documents, which returns brochures and reports rather than authentication interfaces. It is used when hunting exposed documents containing sensitive metadata or credentials, not for locating login portals, which require querying page titles or URL paths such as inurl:login.

  • ✗

    link:example.com

    Why it's wrong here

    link:example.com returns pages containing hyperlinks pointing to that domain, mapping inbound references rather than authentication endpoints. It suits backlink and relationship reconnaissance, whereas finding exposed login pages requires matching URL path or title text such as inurl:admin or intitle:login.

About these practice questions

Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.