Courseiva
Reconnaissance →mediumMultiple Choice

GPEN Reconnaissance Practice Question

When mapping a target's network infrastructure, why is it important to use multiple WHOIS and regional internet registry (RIR) databases?

⚠ Common exam trap

Students often assume WHOIS is used for finding domain names or DNS records, losing sight of the fact that multiple RIR databases are queried specifically to locate all netblocks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To identify all netblocks owned by the target organization.

Different RIRs manage different geographic segments of IP address space. Relying on a single database may result in an incomplete mapping of the organization's network assets. By aggregating data from various sources like ARIN, RIPE, or APNIC, a tester ensures a more accurate inventory of the target's netblocks. This reconnaissance step is critical for defining the scope of the assessment and identifying infrastructure that might be hosted by third-party providers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To increase the speed of the DNS resolution process.

    Why it's wrong here

    WHOIS data is for ownership and administrative record keeping, not for accelerating DNS resolution. The speed of DNS resolution depends on the configuration of authoritative name servers and local caching. Using multiple registries does not improve network performance; it only improves the accuracy of ownership information for IP addresses.

  • ✗

    To bypass the need for an active port scan.

    Why it's wrong here

    WHOIS lookups provide administrative information, not service availability or port status. While it helps in scoping, it does not replace the need for active scanning to determine which services are actually running. Port scanning is required to verify the technical state of the identified infrastructure regardless of ownership.

  • ✓

    To identify all netblocks owned by the target organization.

    Why this is correct

    Organizations often own IP ranges registered under different regional authorities depending on their global footprint. Using multiple WHOIS databases allows the tester to aggregate these records and build a complete picture of the organization's publicly registered network assets, which is essential for ensuring comprehensive testing of all in-scope infrastructure.

  • ✗

    To automatically detect if a server is running an exploit.

    Why it's wrong here

    WHOIS databases contain registration details and administrative contact information. They do not contain technical information regarding running services, vulnerabilities, or exploit statuses. This information is purely administrative and is distinct from the technical vulnerability assessment data gathered during the active scanning phase of the penetration test.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.