Courseiva

CCNA Reconnaissance Questions

22 questions · Reconnaissance · All types, answers revealed

1
MCQeasy

During the reconnaissance phase of a penetration test, you are examining a target's public-facing web application. You notice that the application returns detailed error messages that include full file paths and database query snippets. Which of the following best describes the primary risk associated with this finding?

A.It causes the application to crash, leading to a denial of service
B.It allows attackers to perform cross-site scripting (XSS) attacks
C.It enables attackers to bypass authentication mechanisms
D.It provides attackers with information that can be used to craft more targeted attacks
AnswerD

Detailed error messages reveal internal file paths, database structure, and query logic, which are valuable for an attacker. This information can be used to identify the technology stack, locate vulnerabilities, and craft precise exploits. For example, knowing the database type and version can help tailor SQL injection payloads. This is a classic information disclosure vulnerability that aids reconnaissance.

Why this answer

Detailed error messages are an information disclosure vulnerability. They reveal internal paths, database queries, and technology details that attackers can use to map the application and plan further attacks. This information is valuable for reconnaissance and can significantly reduce the effort required to exploit other vulnerabilities.

Exam trap

The trap here is assuming that verbose errors directly cause a specific exploit like XSS or authentication bypass, when the real issue is the information leak that enables those attacks.

2
Multi-Selecthard

During OSINT gathering, you are investigating a target's presence on social media and professional networking sites. Which TWO of the following methods are effective for gathering metadata about employees to facilitate future social engineering attacks?

Select 2 answers
A.Extracting EXIF data from public photos
B.Performing a brute-force attack on the corporate firewall
C.Analyzing LinkedIn profiles for job descriptions and software stack mentions
D.Conducting a port scan of the internal network
E.Directly calling the IT helpdesk to request employee email addresses
AnswersA, C

Photos uploaded to social media or corporate blogs often contain EXIF metadata, including GPS coordinates and device hardware details. This data can reveal an employee's daily habits, office location, or preferred hardware, providing a wealth of information for planning physical access attacks or tailoring social engineering lures to the specific environment.

Why this answer

OSINT activities focus on harvesting publicly available information to profile individuals within an organization. By analyzing professional profiles and image metadata, an attacker gains insight into corporate hierarchies and technical stacks. This information is vital for crafting targeted phishing campaigns or pretexting scenarios.

Understanding how to extract this data demonstrates a comprehensive approach to reconnaissance by focusing on the 'human' element alongside technical network infrastructure.

Exam trap

Candidates often select technical network scans instead of social networking and metadata methods, forgetting that social engineering requires gathering human and contextual data rather than just finding open ports.

3
MCQmedium

You are conducting a penetration test for a client and need to enumerate subdomains of example.com to map their external attack surface. During this reconnaissance phase, you decide to use a tool that performs DNS zone transfers. Which of the following is the most appropriate tool to attempt a DNS zone transfer?

A.traceroute
B.dig
C.nmap
D.whois
AnswerB

dig is a flexible DNS lookup utility that can perform zone transfers using the AXFR query type. By running 'dig axfr @nameserver example.com', you can attempt to retrieve the entire zone file if the nameserver is misconfigured to allow transfers. This directly aligns with the reconnaissance goal of mapping subdomains.

Why this answer

The dig tool is specifically designed for DNS queries and supports the AXFR query type needed for zone transfer attempts. A successful zone transfer can reveal all DNS records, including subdomains, which is invaluable for mapping the target's external footprint. The other tools serve different reconnaissance purposes and cannot perform this function.

Exam trap

The trap here is assuming that any network reconnaissance tool can perform DNS zone transfers, but only dedicated DNS query tools like dig or host are appropriate for this task.

4
MCQmedium

You are conducting external reconnaissance against a target that uses a split-horizon DNS configuration. From the public internet, you query the organization's authoritative name server for the A record of vpn.contoso.com and receive NXDOMAIN. However, you have obtained a leaked internal zone file that shows the same hostname resolving to 10.10.10.50. Which technique would best allow you to identify additional internal-only hostnames without sending traffic to the target's internal network?

A.DNS cache snooping against the recursive resolver used by the organization
B.Zone transfer (AXFR) against each authoritative name server for the domain
C.Certificate transparency log enumeration for the domain
D.Reverse DNS (PTR) lookups against the 10.0.0.0/8 private address space
AnswerC

Certificate transparency logs record every publicly trusted TLS certificate issued for a domain, including subject alternative names. Organizations frequently request certificates for internal-only hostnames, and those names appear in the logs even when public DNS returns NXDOMAIN. Querying CT logs such as crt.sh for contoso.com can therefore reveal internal hostnames without touching the internal network, directly satisfying the requirement.

Why this answer

Certificate transparency logs are a public, append-only record of issued certificates, and they routinely capture subject alternative names for hosts that never appear in public DNS. Because the organization uses split-horizon DNS, public queries return NXDOMAIN for internal names, but the CT logs still disclose them. Querying a CT aggregator for the domain yields those internal hostnames without any traffic to the internal network.

Exam trap

The trap here is assuming that a failed public DNS lookup means a hostname is undiscoverable, when certificate transparency logs can still leak internal names.

5
Multi-Selectmedium

You are performing a reconnaissance task and need to identify the physical location or ownership of an organization's IP space. Which TWO of the following services are standard for this task?

Select 2 answers
A.WHOIS lookups
B.GeoIP databases
C.SSH brute-force tools
D.Packet sniffing on the target's Wi-Fi
E.Web browser history inspection
AnswersA, B

WHOIS is the standard protocol for querying registration databases. It provides the owner, administrative contact, and registered netblocks for a given domain or IP range. This is fundamental for reconnaissance as it confirms the legal and administrative scope of the assets being tested during the engagement.

Why this answer

WHOIS and GeoIP databases are the industry standard for mapping network ownership and physical presence. WHOIS provides the registrant details for netblocks, while GeoIP services attempt to map IP addresses to physical coordinates. Together, they help a penetration tester understand the geographic footprint and administrative ownership of the target infrastructure, which is essential for accurate scoping and reporting of findings.

Exam trap

Students often choose internal vulnerability scanners or packet analyzers, missing that WHOIS and GeoIP are the standard services for identifying IP space location and ownership.

6
MCQmedium

During the reconnaissance phase, you notice a target is using an older, unpatched version of a popular CMS. What is the most appropriate next step?

A.Immediately run a Metasploit exploit module against the server.
B.Research known CVEs for the identified version.
C.Contact the organization's IT department to report the vulnerability.
D.Ignore the CMS and look for other systems.
AnswerB

Researching specific CVEs for the identified CMS version allows the tester to understand the vulnerability's nature and impact. This information is crucial for planning a safe and effective exploitation strategy. It ensures that the subsequent testing phase is focused on valid attack vectors, minimizing the risk of unnecessary system downtime.

Why this answer

Identifying a vulnerable version of a CMS is a major reconnaissance success. The next step is to research known vulnerabilities (CVEs) associated with that version. This allows the tester to plan an exploit strategy without immediately running active, loud scans that might tip off the security team.

This measured approach ensures that the eventual attack is precise, efficient, and well-supported by prior intelligence gathering efforts.

Exam trap

Examinees often jump straight to exploiting or aggressively scanning the CMS, forgetting that the proper reconnaissance step is to research known CVEs first.

7
Multi-Selecthard

You are conducting passive reconnaissance against a target organization and want to identify internet-facing systems and services without sending any packets to the target's own IP space. Which two techniques best satisfy this requirement? (Choose two.)

Select 2 answers
A.Running an Nmap SYN scan with a low timing template against the target's external ranges
B.Reviewing historical WHOIS and ASN data to map the organization's owned netblocks
C.Using a web application scanner to crawl the target's public website for hidden directories
D.Performing DNS zone transfer attempts against each authoritative name server
E.Querying Shodan for the organization's netblock to review indexed banners and open ports
AnswersB, E

WHOIS and ASN records are public registries that document which netblocks an organization owns or leases. Reviewing them requires queries to registry databases, not to the target's IP space, so the activity remains passive. The resulting netblock map is essential for scoping later queries against third-party scan databases and for understanding the organization's internet footprint.

Why this answer

Querying Shodan leverages a third-party scan database that already collected banners and port states, and reviewing WHOIS and ASN registries maps owned netblocks through public records. Neither technique sends packets to the target's IP space, so both remain passive. Together they provide a service inventory and an address inventory, which are the core outputs needed for passive internet-facing reconnaissance.

Exam trap

The trap here is treating a zone transfer attempt as passive because it is a single DNS query, when it actually reaches the target's authoritative name servers.

8
MCQmedium

Why is it important to perform reconnaissance from a non-attributable source during a penetration test?

A.To improve the speed of data transfer during scans.
B.To avoid triggering security alerts that block the tester's IP.
C.To bypass the need for explicit written authorization.
D.To increase the accuracy of vulnerability detection tools.
AnswerB

Organizations often monitor for scanning activity and blacklist source IPs associated with malicious behavior. By using non-attributable sources, the tester ensures that if one source is detected and blocked, the testing engagement can continue from another, thus preventing a single block from prematurely ending the reconnaissance phase.

Why this answer

Using non-attributable sources, such as a VPN or a compromised proxy, prevents the target from tracing reconnaissance activities back to the testing firm or the specific tester. This protects the anonymity of the test, ensuring that the target's security response is triggered based on the activity itself, rather than by blocking a known testing IP. This is essential for simulating a realistic threat actor's behavior and avoiding early detection.

Exam trap

Students mistakenly think non-attributable sources are meant to bypass encryption or increase scan speed, rather than protecting the tester's IP from being blocked by security alerts.

9
Multi-Selectmedium

During a penetration test, you are performing passive reconnaissance against a target organization. You want to gather information about the organization's public-facing infrastructure without directly interacting with their systems. Which two of the following techniques are considered passive reconnaissance? (Choose two.)

Select 2 answers
A.Querying WHOIS databases for domain registration details
B.Performing a DNS zone transfer against the target's name server
C.Using Shodan to search for exposed services on the target's IP addresses
D.Browsing the target's public website and analyzing its content
E.Conducting a TCP SYN scan on the target's public IP addresses
AnswersA, C

Querying WHOIS databases is a passive technique because it retrieves information from third-party registries, not the target's systems. This can reveal registrar details, name servers, and contact information without alerting the target. It is a standard part of passive reconnaissance.

Why this answer

Passive reconnaissance involves gathering information without directly interacting with the target's systems. Querying WHOIS databases and using Shodan both rely on third-party data sources, so they do not send traffic to the target. In contrast, DNS zone transfers and TCP SYN scans directly interact with the target's infrastructure, making them active techniques.

Browsing a website, while often low-risk, still involves direct interaction and may be logged.

Exam trap

The trap here is thinking that any reconnaissance that doesn't use intrusive tools is passive; however, even a simple DNS query to the target's name server is active because it touches their infrastructure.

10
MCQhard

You are conducting a penetration test and have gained access to a target's internal network. You want to perform reconnaissance to identify other live hosts and services without using traditional port scanning that might trigger IDS alerts. Which of the following techniques would be most effective for low-noise host discovery on the internal network?

A.TCP SYN scan using nmap
B.UDP scan using nmap
C.ARP scanning using arp-scan
D.ICMP ping sweep using fping
AnswerC

ARP scanning sends ARP requests to all IPs in a subnet. Since ARP is a Layer 2 protocol, it does not traverse routers and is not typically monitored by IDS. It is fast, accurate, and stealthy for discovering live hosts on the local subnet. This makes it ideal for low-noise internal reconnaissance.

Why this answer

ARP scanning is a Layer 2 technique that discovers live hosts by sending ARP requests. Since ARP is essential for local network communication, it is rarely filtered or monitored by IDS. This makes it a stealthy and effective method for internal host discovery.

The other techniques involve IP or TCP/UDP packets that can be detected or blocked, making them less suitable for low-noise reconnaissance.

Exam trap

The trap here is assuming that any scan with nmap is stealthy, but on a local network, ARP scanning is far less likely to trigger alerts than TCP or ICMP-based scans.

11
MCQhard

You are analyzing the results of a passive reconnaissance scan using a tool that harvests metadata from files found on a company website. What is the primary security risk associated with this information disclosure?

A.The files can be used to execute arbitrary commands on the client machine.
B.It discloses internal network naming conventions and software versions.
C.It indicates the current load on the corporate web server.
D.It bypasses the need for an external vulnerability assessment.
AnswerB

Metadata often contains fields like 'creator' or 'last modified by,' which can reveal internal usernames. Furthermore, the software version used to generate the file can indicate the patching level of the workstations. This provides attackers with concrete targets for crafting specialized phishing lures or identifying vulnerable software versions used internally.

Why this answer

Metadata in files like PDFs or Word documents often includes internal paths, printer names, software versions used for creation, and author usernames. This information is a goldmine for an attacker attempting to build a social engineering lure or profile the target's workstation environment. Understanding that reconnaissance extends beyond network headers to document analysis is a hallmark of an advanced penetration tester who understands holistic information leakage.

Exam trap

Test-takers frequently choose generic malware infection or data loss answers, missing that document metadata specifically exposes internal architecture naming conventions and software versions.

12
MCQmedium

When mapping a target's network infrastructure, why is it important to use multiple WHOIS and regional internet registry (RIR) databases?

A.To increase the speed of the DNS resolution process.
B.To bypass the need for an active port scan.
C.To identify all netblocks owned by the target organization.
D.To automatically detect if a server is running an exploit.
AnswerC

Organizations often own IP ranges registered under different regional authorities depending on their global footprint. Using multiple WHOIS databases allows the tester to aggregate these records and build a complete picture of the organization's publicly registered network assets, which is essential for ensuring comprehensive testing of all in-scope infrastructure.

Why this answer

Different RIRs manage different geographic segments of IP address space. Relying on a single database may result in an incomplete mapping of the organization's network assets. By aggregating data from various sources like ARIN, RIPE, or APNIC, a tester ensures a more accurate inventory of the target's netblocks.

This reconnaissance step is critical for defining the scope of the assessment and identifying infrastructure that might be hosted by third-party providers.

Exam trap

Students often assume WHOIS is used for finding domain names or DNS records, losing sight of the fact that multiple RIR databases are queried specifically to locate all netblocks.

13
MCQeasy

Which of the following describes the purpose of using Google Dorks during the reconnaissance phase of a penetration test?

A.To bypass the target organization's firewall.
B.To identify publicly exposed sensitive files or directories.
C.To execute remote code on the target's web server.
D.To perform a brute-force attack on user credentials.
AnswerB

Google Dorks utilize specific search operators like 'filetype:' or 'inurl:' to locate files like PDFs, spreadsheets, or configuration backups that were accidentally indexed. This helps in identifying sensitive information exposure, such as directory listings or login pages, without ever interacting directly with the target server's network infrastructure.

Why this answer

Google Dorks are advanced search operators that allow testers to find sensitive information inadvertently indexed by search engines. This is a powerful form of passive reconnaissance that requires no interaction with the target infrastructure. By finding publicly exposed configuration files, logs, or login portals, testers can gain valuable intelligence.

Mastering these operators is a fundamental skill for finding 'low hanging fruit' that often gets overlooked by automated scanning tools.

Exam trap

Test-takers frequently confuse active vulnerability scanning with passive Google Dorking, assuming search operators directly exploit systems rather than merely identifying exposed files and directories.

14
MCQeasy

During a penetration test, you are reviewing the results of a WHOIS query for a target domain. You notice the registrant's email address is privacy-protected, but the technical contact email is a generic address at a third-party hosting company. What is the most likely explanation for this finding, and what should you do next to gather more information about the target's infrastructure?

A.The target is using a privacy protection service; you should query the same WHOIS data from a different regional internet registry (RIR) to find the real contact.
B.The target is hiding its true identity; you should attempt to subpoena the hosting provider for the real customer information.
C.The target has outsourced domain management to a hosting provider; you should examine the hosting provider's IP ranges and look for other domains hosted on the same server.
D.The WHOIS data is corrupted; you should use a different WHOIS tool to retrieve the correct registrant information.
AnswerC

A technical contact at a hosting company indicates the domain's DNS and possibly web hosting are managed by that provider. By examining the hosting provider's IP ranges, you can identify other domains hosted on the same infrastructure, which may reveal shared hosting or additional targets. This is a common reconnaissance technique to expand the attack surface and find related assets that might be less protected.

Why this answer

A technical contact at a hosting company typically means the domain is managed by that provider. Examining the hosting provider's IP ranges and looking for other domains on the same server can reveal shared infrastructure, additional targets, and potential weaknesses. This is a standard passive reconnaissance pivot that expands the scope without directly alerting the target.

Exam trap

The trap here is thinking that privacy protection or hosting contacts are dead ends; in reality, they are pivots to the hosting provider's infrastructure, which can yield more targets.

15
MCQeasy

You are reviewing the scope of an upcoming penetration test and need to identify the organization's mail exchangers and the servers authoritative for its DNS zones using only publicly available records. Which DNS record types should you query to obtain this information directly?

A.MX and NS
B.A and AAAA
C.SOA and PTR
D.CNAME and TXT
AnswerA

MX records specify the mail exchangers responsible for accepting email on behalf of the domain, and NS records identify the authoritative name servers for the zone. Querying these two record types directly yields the mail infrastructure and the DNS authority the scenario asks for. Both are publicly available through standard DNS queries, making them ideal for passive reconnaissance.

Why this answer

MX records list the hosts that accept mail for a domain, and NS records list the authoritative name servers for the zone. Querying these two record types directly returns the mail exchangers and DNS authority the tester needs. Both are standard, publicly resolvable records, making them well suited to the reconnaissance phase without generating suspicious traffic.

Exam trap

The trap here is confusing SOA with NS, since the SOA record names a primary server but does not list all authoritative name servers for the zone.

16
MCQeasy

What is the primary benefit of using passive reconnaissance before initiating active scanning?

A.To identify vulnerabilities without touching the server.
B.To minimize the footprint of the testing engagement.
C.To guarantee access to the target's internal network.
D.To bypass the organization's internal intrusion detection systems.
AnswerB

Passive techniques leave no direct trace on the target systems, as no packets are sent to them. This is the safest way to begin an assessment. By gathering as much intelligence as possible through passive means, the tester avoids triggering alarms, giving them more time to plan a stealthy exploitation phase.

Why this answer

Passive reconnaissance gathers information without alerting the target, allowing the tester to build a comprehensive profile without being blocked. This minimizes the risk of triggering security systems early in the engagement. By understanding the organization's architecture through public sources first, the tester can perform more targeted and efficient active scanning later, significantly increasing the probability of success while reducing the likelihood of early detection by the security operations center.

Exam trap

Candidates often confuse passive reconnaissance benefits with gaining root access or bypassing firewalls, overlooking that its main goal is keeping the testing footprint minimal.

17
MCQmedium

You are conducting an external penetration test against a client who uses a split-horizon DNS configuration. You want to identify internal hostnames and IP addresses without sending any traffic to the client's internal network. Which of the following techniques would best accomplish this?

A.Perform DNS cache snooping against the internal recursive resolver
B.Use DNS zone transfer requests against the external authoritative name servers
C.Analyze historical DNS data from passive DNS databases and certificate transparency logs
D.Query the internal DNS server directly using its private IP address
AnswerC

Passive DNS databases and certificate transparency logs aggregate historical DNS resolutions and SSL/TLS certificate issuances without sending any traffic to the target. They can reveal internal hostnames that were previously exposed in public certificates or DNS queries. This is a purely passive technique that aligns with the requirement to avoid internal network traffic.

Why this answer

Split-horizon DNS separates internal and external views, so external queries won't reveal internal names. Passive DNS and certificate transparency logs are public data sources that may contain leaked internal hostnames from misconfigured certificates or historical records. These sources require no interaction with the target's infrastructure, making them ideal for stealthy reconnaissance.

Exam trap

The trap here is assuming that any DNS query against the target's infrastructure is passive, when in fact only third-party data sources like passive DNS and CT logs avoid touching the target.

18
MCQmedium

You are performing OSINT on a target and have collected a list of employee names from LinkedIn. You want to generate likely corporate email addresses and then verify which ones are valid without sending email to the target's mail servers. Which approach best accomplishes this?

A.Use the SMTP VRFY command against the organization's MX host for each candidate address
B.Query a breach-compilation or email-verification API that checks syntax, domain MX, and known breach data
C.Perform a DNS MX lookup for the domain and assume any address at that domain is valid
D.Send a test message to each candidate address and monitor for bounce-backs
AnswerB

Email-verification services and breach-compilation APIs check address syntax, confirm the domain has valid MX records, and cross-reference known breach corpora without contacting the target's mail servers. This approach validates candidate addresses passively, matching the requirement to avoid sending email to the target. It also scales well when you have many name permutations to test from the LinkedIn list.

Why this answer

Email-verification APIs and breach-compilation services evaluate candidate addresses using syntax checks, MX validation, and known breach data without contacting the target's mail servers. This keeps the activity passive while still filtering out invalid addresses. It is the only listed method that both validates individual addresses and avoids direct interaction with the target, satisfying the scenario's constraints.

Exam trap

The trap here is equating a valid MX record with a valid mailbox, when MX only proves the domain accepts mail, not that a specific address exists.

19
MCQmedium

During a reconnaissance project, you use the 'theHarvester' tool against a target. What information is this tool designed to extract?

A.Internal employee passwords from active memory.
B.Emails, subdomains, and user names from public sources.
C.SQL injection vulnerabilities on web forms.
D.Full network topology maps including internal routers.
AnswerB

theHarvester excels at aggregating email addresses, subdomains, and potential usernames from various public sources like Google, Bing, and PGP servers. This data provides the tester with a list of potential targets and infrastructure endpoints, which is a critical initial step for any penetration test that involves social engineering.

Why this answer

theHarvester is a widely used OSINT tool designed to gather emails, subdomains, and hostnames from various public sources like search engines and PGP key servers. This information is vital for mapping the organization's digital footprint and identifying targets for social engineering. Its ability to aggregate this data from multiple sources makes it an essential tool for penetration testers aiming to build a comprehensive map of an organization's public-facing presence.

Exam trap

Candidates often assume the tool performs active scanning or credential brute-forcing, failing to recognize that it is strictly an OSINT tool for gathering information from public, passive sources.

20
Multi-Selecthard

You are performing passive reconnaissance on a target organization that uses a cloud-based email service. You want to gather information about the organization's email infrastructure and potential phishing targets without alerting the target. Which TWO of the following techniques would be most effective and appropriate for this goal? (Choose two.)

Select 2 answers
A.Run a brute-force attack on the target's OWA login page to guess passwords.
B.Perform a dictionary attack against the target's SMTP server to enumerate valid email addresses.
C.Use the Hunter.io API to discover email addresses associated with the target's domain.
D.Send test emails to common addresses like info@ and support@ to see which ones bounce.
E.Query the target's MX records using a public DNS resolver to identify the email provider.
AnswersC, E

Hunter.io aggregates email addresses from public sources such as websites, social media, and data breaches. Querying its API does not contact the target's servers, so it remains passive. It can reveal both generic and personal email addresses, which are useful for phishing simulations or social engineering. This technique is especially effective for cloud-based email services where addresses may not follow a predictable pattern.

Why this answer

Querying MX records via a public resolver reveals the email provider without touching the target. Using Hunter.io's API collects email addresses from third-party databases, also without target contact. Both techniques are passive, effective for mapping email infrastructure, and provide valuable data for phishing or social engineering while avoiding detection.

Exam trap

The trap here is assuming that any email-related enumeration is passive; techniques like SMTP VRFY or sending test emails actively engage the target and are not appropriate when stealth is required.

21
MCQeasy

You are tasked with gathering information about a target organization's employees to craft a phishing campaign. Which of the following tools is specifically designed to collect email addresses, subdomains, and hostnames from public sources like search engines and PGP key servers?

A.Recon-ng
B.Shodan
C.Maltego
D.theHarvester
AnswerD

theHarvester is a reconnaissance tool that gathers emails, subdomains, hosts, employee names, open ports, and banners from public sources. It queries search engines, PGP key servers, and other databases. This makes it ideal for collecting information to support social engineering or phishing campaigns.

Why this answer

theHarvester is specifically built to collect email addresses, subdomains, and hostnames from public sources such as search engines and PGP key servers. Its focused functionality makes it the most appropriate tool for gathering employee information to support a phishing campaign. Other tools may have overlapping capabilities but are not as specialized for this task.

Exam trap

The trap here is assuming that any OSINT tool can harvest emails, but theHarvester is uniquely streamlined for this purpose, whereas others like Maltego or Recon-ng require more configuration.

22
MCQmedium

You are conducting passive reconnaissance against a target that uses a Web Application Firewall (WAF) and a Content Delivery Network (CDN). You want to discover the origin IP address of the web server to bypass the CDN during later testing. Which technique is most likely to reveal the origin IP without sending any traffic to the target's domain?

A.Send HTTP requests with a spoofed Host header to the CDN edge servers.
B.Query the target's SPF record to find the origin IP.
C.Use a third-party service like SecurityTrails to view historical DNS records.
D.Perform a DNS zone transfer against the target's authoritative nameserver.
AnswerC

SecurityTrails and similar services maintain historical DNS data. Before the target adopted a CDN, its A records may have pointed directly to the origin IP. By querying these historical records, you can often find the original IP address. This is a passive technique because you are querying a third-party database, not the target. It is highly effective for discovering origin IPs that are now hidden behind a CDN.

Why this answer

Historical DNS records from services like SecurityTrails are a passive way to discover an origin IP that was used before the CDN was implemented. Because the data is stored by a third party, querying it does not touch the target's CDN or origin. This makes it a safe and effective method for bypassing CDN obfuscation during reconnaissance.

Exam trap

The trap here is assuming that any DNS query is passive; querying the target's nameserver directly is active, while querying a third-party historical database is passive.

Ready to test yourself?

Try a timed practice session using only Reconnaissance questions.