GPEN Reconnaissance Practice Question
You are conducting external reconnaissance against a target that uses a split-horizon DNS configuration. From the public internet, you query the organization's authoritative name server for the A record of vpn.contoso.com and receive NXDOMAIN. However, you have obtained a leaked internal zone file that shows the same hostname resolving to 10.10.10.50. Which technique would best allow you to identify additional internal-only hostnames without sending traffic to the target's internal network?
⚠ Common exam trap
The trap here is assuming that a failed public DNS lookup means a hostname is undiscoverable, when certificate transparency logs can still leak internal names.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Certificate transparency log enumeration for the domain
Certificate transparency logs are a public, append-only record of issued certificates, and they routinely capture subject alternative names for hosts that never appear in public DNS. Because the organization uses split-horizon DNS, public queries return NXDOMAIN for internal names, but the CT logs still disclose them. Querying a CT aggregator for the domain yields those internal hostnames without any traffic to the internal network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS cache snooping against the recursive resolver used by the organization
Why it's wrong here
Cache snooping checks whether a recursive resolver already has a given record cached; it can confirm that someone queried a name, but it does not enumerate unknown internal hostnames. It also requires access to the organization's recursive resolver, which is typically internal. Against split-horizon DNS, the public resolver would not hold private-zone records, so this technique cannot discover the additional internal names.
- ✗
Zone transfer (AXFR) against each authoritative name server for the domain
Why it's wrong here
An AXFR zone transfer is a legitimate DNS replication mechanism, but modern authoritative servers rarely allow transfers to arbitrary clients. Because the target uses split-horizon DNS, the public authoritative server likely contains only public records, so even a permitted transfer would not reveal the internal-only hostnames present in the private zone. This technique does not address the split-horizon condition described in the scenario.
- ✓
Certificate transparency log enumeration for the domain
Why this is correct
Certificate transparency logs record every publicly trusted TLS certificate issued for a domain, including subject alternative names. Organizations frequently request certificates for internal-only hostnames, and those names appear in the logs even when public DNS returns NXDOMAIN. Querying CT logs such as crt.sh for contoso.com can therefore reveal internal hostnames without touching the internal network, directly satisfying the requirement.
- ✗
Reverse DNS (PTR) lookups against the 10.0.0.0/8 private address space
Why it's wrong here
Reverse DNS lookups against RFC 1918 private space would require the organization's internal resolvers to answer, and the public internet has no authority for those ranges. Even if responses were obtained, PTR records map addresses to names rather than enumerating hostnames tied to the target domain. This approach sends traffic toward internal infrastructure, which the scenario explicitly seeks to avoid.
Visual reference
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.