Courseiva

GPEN · domain

Reconnaissance

Reconnaissance on the GPEN exam covers passive and active information gathering against a target before exploitation. You must know how OSINT, DNS interrogation, metadata harvesting, and email/username enumeration work, which tools produce which artifacts, and how to interpret findings like leaked hostnames or internal IPs without touching the client's internal network.

22 questions6 easy11 medium5 hard

Focused practice

Practice Reconnaissance questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Reconnaissance

Be able to perform passive and active reconnaissance with DNS tools, metadata harvesters, and OSINT sources, then interpret what leaked hostnames, usernames, and metadata reveal. The most important thing is knowing which techniques stay passive and which generate traffic to the target.

Using whois, dig, host, and nslookup to enumerate DNS records and identify split-horizon discrepancies

Harvesting document metadata with tools like FOCA, metagoofil, or exiftool to extract usernames, paths, and software versions

Collecting employee names via LinkedIn and OSINT sources to build email address patterns for validation

Distinguishing passive reconnaissance techniques from active scanning and explaining the risk tradeoffs of each

Watch out for

Common Reconnaissance exam traps

  • ▸Assuming split-horizon DNS can be enumerated by querying the internal resolver directly, which sends traffic to the client's internal network and violates scope
  • ▸Treating metadata disclosure as low risk when it commonly leaks internal hostnames, usernames, software versions, and filesystem paths useful for later attacks
  • ▸Confusing passive OSINT collection with active verification, such as sending email or probes to validate addresses, which crosses into active reconnaissance

Question index

All Reconnaissance questions (22)

Click any question to see the full explanation, or start a practice session above.

1

During the reconnaissance phase of a penetration test, you are examining a target's public-facing web application. You notice that the application returns detailed error messages that include full file paths and database query snippets. Which of the following best describes the primary risk associated with this finding?

Easy
2

During OSINT gathering, you are investigating a target's presence on social media and professional networking sites. Which TWO of the following methods are effective for gathering metadata about employees to facilitate future social engineering attacks?

Hard
3

You are conducting a penetration test for a client and need to enumerate subdomains of example.com to map their external attack surface. During this reconnaissance phase, you decide to use a tool that performs DNS zone transfers. Which of the following is the most appropriate tool to attempt a DNS zone transfer?

Medium
4

You are conducting external reconnaissance against a target that uses a split-horizon DNS configuration. From the public internet, you query the organization's authoritative name server for the A record of vpn.contoso.com and receive NXDOMAIN. However, you have obtained a leaked internal zone file that shows the same hostname resolving to 10.10.10.50. Which technique would best allow you to identify additional internal-only hostnames without sending traffic to the target's internal network?

Medium
5

You are performing a reconnaissance task and need to identify the physical location or ownership of an organization's IP space. Which TWO of the following services are standard for this task?

Medium
6

During the reconnaissance phase, you notice a target is using an older, unpatched version of a popular CMS. What is the most appropriate next step?

Medium
7

You are conducting passive reconnaissance against a target organization and want to identify internet-facing systems and services without sending any packets to the target's own IP space. Which two techniques best satisfy this requirement? (Choose two.)

Hard
8

Why is it important to perform reconnaissance from a non-attributable source during a penetration test?

Medium
9

During a penetration test, you are performing passive reconnaissance against a target organization. You want to gather information about the organization's public-facing infrastructure without directly interacting with their systems. Which two of the following techniques are considered passive reconnaissance? (Choose two.)

Medium
10

You are conducting a penetration test and have gained access to a target's internal network. You want to perform reconnaissance to identify other live hosts and services without using traditional port scanning that might trigger IDS alerts. Which of the following techniques would be most effective for low-noise host discovery on the internal network?

Hard
11

You are analyzing the results of a passive reconnaissance scan using a tool that harvests metadata from files found on a company website. What is the primary security risk associated with this information disclosure?

Hard
12

When mapping a target's network infrastructure, why is it important to use multiple WHOIS and regional internet registry (RIR) databases?

Medium
13

Which of the following describes the purpose of using Google Dorks during the reconnaissance phase of a penetration test?

Easy
14

During a penetration test, you are reviewing the results of a WHOIS query for a target domain. You notice the registrant's email address is privacy-protected, but the technical contact email is a generic address at a third-party hosting company. What is the most likely explanation for this finding, and what should you do next to gather more information about the target's infrastructure?

Easy
15

You are reviewing the scope of an upcoming penetration test and need to identify the organization's mail exchangers and the servers authoritative for its DNS zones using only publicly available records. Which DNS record types should you query to obtain this information directly?

Easy
16

What is the primary benefit of using passive reconnaissance before initiating active scanning?

Easy
17

You are conducting an external penetration test against a client who uses a split-horizon DNS configuration. You want to identify internal hostnames and IP addresses without sending any traffic to the client's internal network. Which of the following techniques would best accomplish this?

Medium
18

You are performing OSINT on a target and have collected a list of employee names from LinkedIn. You want to generate likely corporate email addresses and then verify which ones are valid without sending email to the target's mail servers. Which approach best accomplishes this?

Medium
19

During a reconnaissance project, you use the 'theHarvester' tool against a target. What information is this tool designed to extract?

Medium
20

You are performing passive reconnaissance on a target organization that uses a cloud-based email service. You want to gather information about the organization's email infrastructure and potential phishing targets without alerting the target. Which TWO of the following techniques would be most effective and appropriate for this goal? (Choose two.)

Hard
21

You are tasked with gathering information about a target organization's employees to craft a phishing campaign. Which of the following tools is specifically designed to collect email addresses, subdomains, and hostnames from public sources like search engines and PGP key servers?

Easy
22

You are conducting passive reconnaissance against a target that uses a Web Application Firewall (WAF) and a Content Delivery Network (CDN). You want to discover the origin IP address of the web server to bypass the CDN during later testing. Which technique is most likely to reveal the origin IP without sending any traffic to the target's domain?

Medium

Frequently asked questions

What does the Reconnaissance domain cover on the GPEN exam?
Be able to perform passive and active reconnaissance with DNS tools, metadata harvesters, and OSINT sources, then interpret what leaked hostnames, usernames, and metadata reveal. The most important thing is knowing which techniques stay passive and which generate traffic to the target.
How many questions are in this domain?
This page lists all 22 Reconnaissance questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Reconnaissance questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gpen GIAC-GPEN reconnaissance Practice Questions