Courseiva

GPEN · topic practice

Reconnaissance practice questions

Reconnaissance on the GPEN exam covers passive and active information gathering against a target before exploitation. You must know how OSINT, DNS interrogation, metadata harvesting, and email/username enumeration work, which tools produce which artifacts, and how to interpret findings like leaked hostnames or internal IPs without touching the client's internal network.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Reconnaissance

What the exam tests

What to know about Reconnaissance

Be able to perform passive and active reconnaissance with DNS tools, metadata harvesters, and OSINT sources, then interpret what leaked hostnames, usernames, and metadata reveal. The most important thing is knowing which techniques stay passive and which generate traffic to the target.

Using whois, dig, host, and nslookup to enumerate DNS records and identify split-horizon discrepancies

Harvesting document metadata with tools like FOCA, metagoofil, or exiftool to extract usernames, paths, and software versions

Collecting employee names via LinkedIn and OSINT sources to build email address patterns for validation

Distinguishing passive reconnaissance techniques from active scanning and explaining the risk tradeoffs of each

Watch out for

Common Reconnaissance exam traps

  • ▸Assuming split-horizon DNS can be enumerated by querying the internal resolver directly, which sends traffic to the client's internal network and violates scope
  • ▸Treating metadata disclosure as low risk when it commonly leaks internal hostnames, usernames, software versions, and filesystem paths useful for later attacks
  • ▸Confusing passive OSINT collection with active verification, such as sending email or probes to validate addresses, which crosses into active reconnaissance

Practice set

Reconnaissance questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full DNS explanation →

You are performing passive reconnaissance on a target organization. You decide to query DNS records to find subdomains that might be out of scope for the primary security team. Which tool is most effective for extracting subdomains via DNS zone transfers and brute-forcing common records?

Question 2mediummulti select
Read the full DNS explanation →

During passive reconnaissance, you are analyzing an organization's public DNS records. Which THREE of the following record types are most useful for identifying infrastructure details?

You are tasked with gathering intelligence on an organization's cloud infrastructure. Which TWO of the following techniques would be most effective for discovering cloud-hosted assets?

Question 4mediummultiple choice
Read the full Reconnaissance explanation →

You are performing passive reconnaissance on a target organization. You decide to search for leaked credentials and sensitive configuration files indexed by public search engines. Which tool is most effective for automating advanced dorking queries to identify exposed administrative interfaces?

You are performing passive reconnaissance against a target organization that uses a cloud-based email service. You want to identify employee email addresses and verify which ones are valid without triggering alerting mechanisms. Which TWO of the following techniques would best accomplish this? (Choose two.)

During a penetration test, you are performing active reconnaissance on a target network. You want to identify live hosts without sending traditional ICMP echo requests, which are often blocked by firewalls. Which of the following nmap scan techniques would best accomplish this by using TCP SYN packets to common ports?

During an external penetration test, you want to enumerate hostnames and IP addresses associated with the target organization without triggering alerts on its perimeter. You have no prior relationship with the target and must rely solely on publicly available data. Which combination of resources would most directly provide a historical mapping of the organization's internet-facing infrastructure?

Question 8mediummultiple choice
Read the full Reconnaissance explanation →

During an authorized penetration test, you need to enumerate email addresses and employee names for a target organization without triggering any IDS alerts. You decide to use theHarvester. Which data source should you configure to maximize passive OSINT collection while ensuring zero direct contact with the target's infrastructure?

Question 9easymultiple choice
Read the full DNS explanation →

You are conducting passive reconnaissance against a target that uses a split-horizon DNS configuration. You have obtained a list of subdomains from a public certificate transparency log. Which action should you take next to determine which subdomains resolve to internal IP addresses without sending DNS queries to the target's authoritative nameservers?

During OSINT gathering, you are investigating a target's presence on social media and professional networking sites. Which TWO of the following methods are effective for gathering metadata about employees to facilitate future social engineering attacks?

Question 11easymultiple choice
Read the full Reconnaissance explanation →

Which of the following describes the purpose of using Google Dorks during the reconnaissance phase of a penetration test?

Question 12mediummultiple choice
Read the full Reconnaissance explanation →

When mapping a target's network infrastructure, why is it important to use multiple WHOIS and regional internet registry (RIR) databases?

Question 13hardmultiple choice
Read the full Reconnaissance explanation →

You are analyzing the results of a passive reconnaissance scan using a tool that harvests metadata from files found on a company website. What is the primary security risk associated with this information disclosure?

Question 14mediummultiple choice
Read the full Reconnaissance explanation →

Why is it important to perform reconnaissance from a non-attributable source during a penetration test?

Question 15mediummultiple choice
Read the full Reconnaissance explanation →

During the reconnaissance phase, you notice a target is using an older, unpatched version of a popular CMS. What is the most appropriate next step?

Question 16easymultiple choice
Read the full Reconnaissance explanation →

What is the primary benefit of using passive reconnaissance before initiating active scanning?

You are performing a reconnaissance task and need to identify the physical location or ownership of an organization's IP space. Which TWO of the following services are standard for this task?

Question 18mediummultiple choice
Read the full Reconnaissance explanation →

During a reconnaissance project, you use the 'theHarvester' tool against a target. What information is this tool designed to extract?

Question 19mediummultiple choice
Read the full DNS explanation →

You are conducting an external penetration test against a client who uses a split-horizon DNS configuration. You want to identify internal hostnames and IP addresses without sending any traffic to the client's internal network. Which of the following techniques would best accomplish this?

Question 20mediummultiple choice
Read the full DNS explanation →

You are conducting a penetration test for a client and need to enumerate subdomains of example.com to map their external attack surface. During this reconnaissance phase, you decide to use a tool that performs DNS zone transfers. Which of the following is the most appropriate tool to attempt a DNS zone transfer?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Reconnaissance sessions

Start a Reconnaissance only practice session

Every question in these sessions is drawn from the Reconnaissance domain — nothing else.

Related practice questions

Related GPEN topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GPEN exam test about Reconnaissance?
Be able to perform passive and active reconnaissance with DNS tools, metadata harvesters, and OSINT sources, then interpret what leaked hostnames, usernames, and metadata reveal. The most important thing is knowing which techniques stay passive and which generate traffic to the target.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Reconnaissance questions in a focused session?
Yes — the session launcher on this page draws every question from the Reconnaissance domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GPEN topics?
Use the topic links above to move to related areas, or go back to the GPEN question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GPEN exam covers. They are not copied from any real exam or dump site.