Courseiva
Reconnaissance →mediumMultiple Choice

GPEN Reconnaissance Practice Question

You are conducting external reconnaissance against a target that uses a split-horizon DNS configuration. From the public internet, you query the organization's authoritative name server for the A record of vpn.contoso.com and receive NXDOMAIN. However, you have obtained a leaked internal zone file that shows the same hostname resolving to 10.10.10.50. Which technique would best allow you to identify additional internal-only hostnames without sending traffic to the target's internal network?

⚠ Common exam trap

The trap here is assuming that a failed public DNS lookup means a hostname is undiscoverable, when certificate transparency logs can still leak internal names.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Certificate transparency log enumeration for the domain

Certificate transparency logs are a public, append-only record of issued certificates, and they routinely capture subject alternative names for hosts that never appear in public DNS. Because the organization uses split-horizon DNS, public queries return NXDOMAIN for internal names, but the CT logs still disclose them. Querying a CT aggregator for the domain yields those internal hostnames without any traffic to the internal network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS cache snooping against the recursive resolver used by the organization

    Why it's wrong here

    Cache snooping checks whether a recursive resolver already has a given record cached; it can confirm that someone queried a name, but it does not enumerate unknown internal hostnames. It also requires access to the organization's recursive resolver, which is typically internal. Against split-horizon DNS, the public resolver would not hold private-zone records, so this technique cannot discover the additional internal names.

  • ✗

    Zone transfer (AXFR) against each authoritative name server for the domain

    Why it's wrong here

    An AXFR zone transfer is a legitimate DNS replication mechanism, but modern authoritative servers rarely allow transfers to arbitrary clients. Because the target uses split-horizon DNS, the public authoritative server likely contains only public records, so even a permitted transfer would not reveal the internal-only hostnames present in the private zone. This technique does not address the split-horizon condition described in the scenario.

  • ✓

    Certificate transparency log enumeration for the domain

    Why this is correct

    Certificate transparency logs record every publicly trusted TLS certificate issued for a domain, including subject alternative names. Organizations frequently request certificates for internal-only hostnames, and those names appear in the logs even when public DNS returns NXDOMAIN. Querying CT logs such as crt.sh for contoso.com can therefore reveal internal hostnames without touching the internal network, directly satisfying the requirement.

  • ✗

    Reverse DNS (PTR) lookups against the 10.0.0.0/8 private address space

    Why it's wrong here

    Reverse DNS lookups against RFC 1918 private space would require the organization's internal resolvers to answer, and the public internet has no authority for those ranges. Even if responses were obtained, PTR records map addresses to names rather than enumerating hostnames tied to the target domain. This approach sends traffic toward internal infrastructure, which the scenario explicitly seeks to avoid.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.