Courseiva
Reconnaissance →hardMultiple Select

GPEN Reconnaissance Practice Question

You are conducting passive reconnaissance against a target organization and want to identify internet-facing systems and services without sending any packets to the target's own IP space. Which two techniques best satisfy this requirement? (Choose two.)

⚠ Common exam trap

The trap here is treating a zone transfer attempt as passive because it is a single DNS query, when it actually reaches the target's authoritative name servers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reviewing historical WHOIS and ASN data to map the organization's owned netblocks

Querying Shodan leverages a third-party scan database that already collected banners and port states, and reviewing WHOIS and ASN registries maps owned netblocks through public records. Neither technique sends packets to the target's IP space, so both remain passive. Together they provide a service inventory and an address inventory, which are the core outputs needed for passive internet-facing reconnaissance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Running an Nmap SYN scan with a low timing template against the target's external ranges

    Why it's wrong here

    An Nmap SYN scan sends TCP SYN packets to the target's IP ranges, which is active reconnaissance and violates the requirement to avoid sending packets to the target's own IP space. Even a low timing template still generates traffic that could appear in the target's logs or trigger IDS alerts. This technique is therefore unsuitable for the stated passive-only constraint.

  • ✓

    Reviewing historical WHOIS and ASN data to map the organization's owned netblocks

    Why this is correct

    WHOIS and ASN records are public registries that document which netblocks an organization owns or leases. Reviewing them requires queries to registry databases, not to the target's IP space, so the activity remains passive. The resulting netblock map is essential for scoping later queries against third-party scan databases and for understanding the organization's internet footprint.

  • ✗

    Using a web application scanner to crawl the target's public website for hidden directories

    Why it's wrong here

    A web application scanner requests pages and directories from the target's web servers, generating HTTP traffic that reaches target-owned infrastructure. This is active reconnaissance and could be detected by web application firewalls or logged in access logs. It also focuses on web content rather than the broader internet-facing system and service inventory the scenario seeks.

  • ✗

    Performing DNS zone transfer attempts against each authoritative name server

    Why it's wrong here

    A zone transfer attempt sends a DNS query directly to the target's authoritative name servers, which counts as active reconnaissance against the target's infrastructure. Even though it is a single query, it reaches target-owned systems and may be logged. It also rarely succeeds on properly configured servers, so it fails both the passive requirement and the reliability expectation.

  • ✓

    Querying Shodan for the organization's netblock to review indexed banners and open ports

    Why this is correct

    Shodan continuously scans the internet and stores banners, port states, and service metadata. Querying it for the organization's netblock returns information that was collected by Shodan's own scanners, not by you, so no packets are sent to the target. This directly satisfies the passive requirement while still revealing internet-facing systems and services.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.