GPEN Reconnaissance Practice Question
During a penetration test, you are reviewing the results of a WHOIS query for a target domain. You notice the registrant's email address is privacy-protected, but the technical contact email is a generic address at a third-party hosting company. What is the most likely explanation for this finding, and what should you do next to gather more information about the target's infrastructure?
⚠ Common exam trap
The trap here is thinking that privacy protection or hosting contacts are dead ends; in reality, they are pivots to the hosting provider's infrastructure, which can yield more targets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The target has outsourced domain management to a hosting provider; you should examine the hosting provider's IP ranges and look for other domains hosted on the same server.
A technical contact at a hosting company typically means the domain is managed by that provider. Examining the hosting provider's IP ranges and looking for other domains on the same server can reveal shared infrastructure, additional targets, and potential weaknesses. This is a standard passive reconnaissance pivot that expands the scope without directly alerting the target.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The target is using a privacy protection service; you should query the same WHOIS data from a different regional internet registry (RIR) to find the real contact.
Why it's wrong here
While privacy protection services do mask registrant details, the technical contact being a hosting company suggests the domain is managed by a third party. Querying a different RIR may not help because WHOIS data is typically consistent across RIRs for the same domain. The real information might be in the hosting company's records, but that requires a different approach, such as examining the hosting provider's infrastructure or looking for subdomains that point to the target's own IP space.
- ✗
The target is hiding its true identity; you should attempt to subpoena the hosting provider for the real customer information.
Why it's wrong here
Subpoenaing a hosting provider is a legal action that is outside the scope of a penetration test and inappropriate for reconnaissance. It also assumes malicious intent, whereas outsourcing domain management is a normal business practice. This option is not a technical reconnaissance step and would not be pursued during a standard engagement. It also does not help gather technical information about the infrastructure.
- ✓
The target has outsourced domain management to a hosting provider; you should examine the hosting provider's IP ranges and look for other domains hosted on the same server.
Why this is correct
A technical contact at a hosting company indicates the domain's DNS and possibly web hosting are managed by that provider. By examining the hosting provider's IP ranges, you can identify other domains hosted on the same infrastructure, which may reveal shared hosting or additional targets. This is a common reconnaissance technique to expand the attack surface and find related assets that might be less protected.
- ✗
The WHOIS data is corrupted; you should use a different WHOIS tool to retrieve the correct registrant information.
Why it's wrong here
The WHOIS data is not corrupted; it accurately reflects that the domain's technical contact is the hosting company. Using a different WHOIS tool will return the same information. The presence of a hosting company contact is a deliberate choice, not an error. To gather more information, you should pivot to analyzing the hosting provider's infrastructure rather than trying to 'fix' the WHOIS query.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.