Courseiva
Reconnaissance →hardMultiple Choice

GPEN Reconnaissance Practice Question

You are analyzing the results of a passive reconnaissance scan using a tool that harvests metadata from files found on a company website. What is the primary security risk associated with this information disclosure?

⚠ Common exam trap

Test-takers frequently choose generic malware infection or data loss answers, missing that document metadata specifically exposes internal architecture naming conventions and software versions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It discloses internal network naming conventions and software versions.

Metadata in files like PDFs or Word documents often includes internal paths, printer names, software versions used for creation, and author usernames. This information is a goldmine for an attacker attempting to build a social engineering lure or profile the target's workstation environment. Understanding that reconnaissance extends beyond network headers to document analysis is a hallmark of an advanced penetration tester who understands holistic information leakage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The files can be used to execute arbitrary commands on the client machine.

    Why it's wrong here

    Metadata harvesting itself does not execute code. While the files might contain malicious macros, the act of extracting metadata is a passive read-only operation. The risk lies in the information disclosed within the metadata, not in the metadata extraction tool's ability to trigger code execution on the client.

  • ✓

    It discloses internal network naming conventions and software versions.

    Why this is correct

    Metadata often contains fields like 'creator' or 'last modified by,' which can reveal internal usernames. Furthermore, the software version used to generate the file can indicate the patching level of the workstations. This provides attackers with concrete targets for crafting specialized phishing lures or identifying vulnerable software versions used internally.

  • ✗

    It indicates the current load on the corporate web server.

    Why it's wrong here

    Metadata relates to the file's creation and properties, not the server's operational load. Server load is determined by analyzing response times or specialized headers, not file-level metadata. Therefore, metadata analysis is an ineffective method for measuring the server's current resource utilization or performance metrics during reconnaissance.

  • ✗

    It bypasses the need for an external vulnerability assessment.

    Why it's wrong here

    Metadata is just one piece of the reconnaissance puzzle. It does not replace the need for vulnerability assessment, which identifies weaknesses in the technical infrastructure. While metadata provides clues, a full assessment is required to validate the actual security posture of the systems and applications being analyzed.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.