Courseiva
Reconnaissance →mediumMultiple Choice

GPEN Reconnaissance Practice Question

You are conducting passive reconnaissance against a target that uses a Web Application Firewall (WAF) and a Content Delivery Network (CDN). You want to discover the origin IP address of the web server to bypass the CDN during later testing. Which technique is most likely to reveal the origin IP without sending any traffic to the target's domain?

⚠ Common exam trap

The trap here is assuming that any DNS query is passive; querying the target's nameserver directly is active, while querying a third-party historical database is passive.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a third-party service like SecurityTrails to view historical DNS records.

Historical DNS records from services like SecurityTrails are a passive way to discover an origin IP that was used before the CDN was implemented. Because the data is stored by a third party, querying it does not touch the target's CDN or origin. This makes it a safe and effective method for bypassing CDN obfuscation during reconnaissance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Send HTTP requests with a spoofed Host header to the CDN edge servers.

    Why it's wrong here

    Sending requests with a spoofed Host header to the CDN is an active technique. It may sometimes cause the CDN to route the request to the origin, but it involves direct interaction with the CDN, which is part of the target's public-facing infrastructure. This can be logged and may not reveal the origin IP directly. It is not passive and carries a higher risk of detection.

  • ✗

    Query the target's SPF record to find the origin IP.

    Why it's wrong here

    SPF records list authorized sending hosts for email, not web servers. They typically include IP addresses of mail servers or third-party email providers, but rarely the web server's origin IP. While SPF records can sometimes reveal infrastructure, they are not designed to expose web origin addresses. This technique is unlikely to yield the web server's IP and may send you on a wild goose chase.

  • ✓

    Use a third-party service like SecurityTrails to view historical DNS records.

    Why this is correct

    SecurityTrails and similar services maintain historical DNS data. Before the target adopted a CDN, its A records may have pointed directly to the origin IP. By querying these historical records, you can often find the original IP address. This is a passive technique because you are querying a third-party database, not the target. It is highly effective for discovering origin IPs that are now hidden behind a CDN.

  • ✗

    Perform a DNS zone transfer against the target's authoritative nameserver.

    Why it's wrong here

    A DNS zone transfer is an active query sent to the target's nameserver. It may reveal internal records if misconfigured, but it directly contacts the target's infrastructure and is easily logged. Moreover, modern CDN setups often use separate nameservers that do not hold the origin IP. This technique is not passive and is unlikely to succeed in a well-configured environment.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.