GPEN Reconnaissance Practice Question
You are conducting passive reconnaissance against a target that uses a Web Application Firewall (WAF) and a Content Delivery Network (CDN). You want to discover the origin IP address of the web server to bypass the CDN during later testing. Which technique is most likely to reveal the origin IP without sending any traffic to the target's domain?
⚠ Common exam trap
The trap here is assuming that any DNS query is passive; querying the target's nameserver directly is active, while querying a third-party historical database is passive.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a third-party service like SecurityTrails to view historical DNS records.
Historical DNS records from services like SecurityTrails are a passive way to discover an origin IP that was used before the CDN was implemented. Because the data is stored by a third party, querying it does not touch the target's CDN or origin. This makes it a safe and effective method for bypassing CDN obfuscation during reconnaissance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Send HTTP requests with a spoofed Host header to the CDN edge servers.
Why it's wrong here
Sending requests with a spoofed Host header to the CDN is an active technique. It may sometimes cause the CDN to route the request to the origin, but it involves direct interaction with the CDN, which is part of the target's public-facing infrastructure. This can be logged and may not reveal the origin IP directly. It is not passive and carries a higher risk of detection.
- ✗
Query the target's SPF record to find the origin IP.
Why it's wrong here
SPF records list authorized sending hosts for email, not web servers. They typically include IP addresses of mail servers or third-party email providers, but rarely the web server's origin IP. While SPF records can sometimes reveal infrastructure, they are not designed to expose web origin addresses. This technique is unlikely to yield the web server's IP and may send you on a wild goose chase.
- ✓
Use a third-party service like SecurityTrails to view historical DNS records.
Why this is correct
SecurityTrails and similar services maintain historical DNS data. Before the target adopted a CDN, its A records may have pointed directly to the origin IP. By querying these historical records, you can often find the original IP address. This is a passive technique because you are querying a third-party database, not the target. It is highly effective for discovering origin IPs that are now hidden behind a CDN.
- ✗
Perform a DNS zone transfer against the target's authoritative nameserver.
Why it's wrong here
A DNS zone transfer is an active query sent to the target's nameserver. It may reveal internal records if misconfigured, but it directly contacts the target's infrastructure and is easily logged. Moreover, modern CDN setups often use separate nameservers that do not hold the origin IP. This technique is not passive and is unlikely to succeed in a well-configured environment.
Visual reference
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.