GPEN · domain
Reconnaissance
Reconnaissance on the GPEN exam covers passive and active information gathering against a target before exploitation. You must know how OSINT, DNS interrogation, metadata harvesting, and email/username enumeration work, which tools produce which artifacts, and how to interpret findings like leaked hostnames or internal IPs without touching the client's internal network.
Focused practice
Practice Reconnaissance questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Reconnaissance
Be able to perform passive and active reconnaissance with DNS tools, metadata harvesters, and OSINT sources, then interpret what leaked hostnames, usernames, and metadata reveal. The most important thing is knowing which techniques stay passive and which generate traffic to the target.
Using whois, dig, host, and nslookup to enumerate DNS records and identify split-horizon discrepancies
Harvesting document metadata with tools like FOCA, metagoofil, or exiftool to extract usernames, paths, and software versions
Collecting employee names via LinkedIn and OSINT sources to build email address patterns for validation
Distinguishing passive reconnaissance techniques from active scanning and explaining the risk tradeoffs of each
Watch out for
Common Reconnaissance exam traps
- ▸Assuming split-horizon DNS can be enumerated by querying the internal resolver directly, which sends traffic to the client's internal network and violates scope
- ▸Treating metadata disclosure as low risk when it commonly leaks internal hostnames, usernames, software versions, and filesystem paths useful for later attacks
- ▸Confusing passive OSINT collection with active verification, such as sending email or probes to validate addresses, which crosses into active reconnaissance
Question index
All Reconnaissance questions (22)
Click any question to see the full explanation, or start a practice session above.
During the reconnaissance phase of a penetration test, you are examining a target's public-facing web application. You notice that the application returns detailed error messages that include full file paths and database query snippets. Which of the following best describes the primary risk associated with this finding?
Easy2During OSINT gathering, you are investigating a target's presence on social media and professional networking sites. Which TWO of the following methods are effective for gathering metadata about employees to facilitate future social engineering attacks?
Hard3You are conducting a penetration test for a client and need to enumerate subdomains of example.com to map their external attack surface. During this reconnaissance phase, you decide to use a tool that performs DNS zone transfers. Which of the following is the most appropriate tool to attempt a DNS zone transfer?
Medium4You are conducting external reconnaissance against a target that uses a split-horizon DNS configuration. From the public internet, you query the organization's authoritative name server for the A record of vpn.contoso.com and receive NXDOMAIN. However, you have obtained a leaked internal zone file that shows the same hostname resolving to 10.10.10.50. Which technique would best allow you to identify additional internal-only hostnames without sending traffic to the target's internal network?
Medium5You are performing a reconnaissance task and need to identify the physical location or ownership of an organization's IP space. Which TWO of the following services are standard for this task?
Medium6During the reconnaissance phase, you notice a target is using an older, unpatched version of a popular CMS. What is the most appropriate next step?
Medium7You are conducting passive reconnaissance against a target organization and want to identify internet-facing systems and services without sending any packets to the target's own IP space. Which two techniques best satisfy this requirement? (Choose two.)
Hard8Why is it important to perform reconnaissance from a non-attributable source during a penetration test?
Medium9During a penetration test, you are performing passive reconnaissance against a target organization. You want to gather information about the organization's public-facing infrastructure without directly interacting with their systems. Which two of the following techniques are considered passive reconnaissance? (Choose two.)
Medium10You are conducting a penetration test and have gained access to a target's internal network. You want to perform reconnaissance to identify other live hosts and services without using traditional port scanning that might trigger IDS alerts. Which of the following techniques would be most effective for low-noise host discovery on the internal network?
Hard11You are analyzing the results of a passive reconnaissance scan using a tool that harvests metadata from files found on a company website. What is the primary security risk associated with this information disclosure?
Hard12When mapping a target's network infrastructure, why is it important to use multiple WHOIS and regional internet registry (RIR) databases?
Medium13Which of the following describes the purpose of using Google Dorks during the reconnaissance phase of a penetration test?
Easy14During a penetration test, you are reviewing the results of a WHOIS query for a target domain. You notice the registrant's email address is privacy-protected, but the technical contact email is a generic address at a third-party hosting company. What is the most likely explanation for this finding, and what should you do next to gather more information about the target's infrastructure?
Easy15You are reviewing the scope of an upcoming penetration test and need to identify the organization's mail exchangers and the servers authoritative for its DNS zones using only publicly available records. Which DNS record types should you query to obtain this information directly?
Easy16What is the primary benefit of using passive reconnaissance before initiating active scanning?
Easy17You are conducting an external penetration test against a client who uses a split-horizon DNS configuration. You want to identify internal hostnames and IP addresses without sending any traffic to the client's internal network. Which of the following techniques would best accomplish this?
Medium18You are performing OSINT on a target and have collected a list of employee names from LinkedIn. You want to generate likely corporate email addresses and then verify which ones are valid without sending email to the target's mail servers. Which approach best accomplishes this?
Medium19During a reconnaissance project, you use the 'theHarvester' tool against a target. What information is this tool designed to extract?
Medium20You are performing passive reconnaissance on a target organization that uses a cloud-based email service. You want to gather information about the organization's email infrastructure and potential phishing targets without alerting the target. Which TWO of the following techniques would be most effective and appropriate for this goal? (Choose two.)
Hard21You are tasked with gathering information about a target organization's employees to craft a phishing campaign. Which of the following tools is specifically designed to collect email addresses, subdomains, and hostnames from public sources like search engines and PGP key servers?
Easy22You are conducting passive reconnaissance against a target that uses a Web Application Firewall (WAF) and a Content Delivery Network (CDN). You want to discover the origin IP address of the web server to bypass the CDN during later testing. Which technique is most likely to reveal the origin IP without sending any traffic to the target's domain?
MediumOther domains
All GPEN exam domains
Frequently asked questions
- What does the Reconnaissance domain cover on the GPEN exam?
- Be able to perform passive and active reconnaissance with DNS tools, metadata harvesters, and OSINT sources, then interpret what leaked hostnames, usernames, and metadata reveal. The most important thing is knowing which techniques stay passive and which generate traffic to the target.
- How many questions are in this domain?
- This page lists all 22 Reconnaissance questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Reconnaissance questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.