Courseiva
Reconnaissance →mediumMultiple Select

GPEN Reconnaissance Practice Question

You are performing a reconnaissance task and need to identify the physical location or ownership of an organization's IP space. Which TWO of the following services are standard for this task?

⚠ Common exam trap

Students often choose internal vulnerability scanners or packet analyzers, missing that WHOIS and GeoIP are the standard services for identifying IP space location and ownership.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WHOIS lookups

WHOIS and GeoIP databases are the industry standard for mapping network ownership and physical presence. WHOIS provides the registrant details for netblocks, while GeoIP services attempt to map IP addresses to physical coordinates. Together, they help a penetration tester understand the geographic footprint and administrative ownership of the target infrastructure, which is essential for accurate scoping and reporting of findings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    WHOIS lookups

    Why this is correct

    WHOIS is the standard protocol for querying registration databases. It provides the owner, administrative contact, and registered netblocks for a given domain or IP range. This is fundamental for reconnaissance as it confirms the legal and administrative scope of the assets being tested during the engagement.

  • ✓

    GeoIP databases

    Why this is correct

    GeoIP services map IP addresses to physical locations, such as cities or countries. This data is critical for understanding where the infrastructure is located, which can provide clues about the organization's global footprint and whether certain servers might be subject to different regional regulations or security controls.

  • ✗

    SSH brute-force tools

    Why it's wrong here

    SSH brute-force tools are used for attempting unauthorized access to a system. They are not for reconnaissance regarding physical location or IP ownership. Engaging in brute-force attacks during the reconnaissance phase is highly intrusive and will likely cause the tester's IP to be blocked, failing the goal of stealthy reconnaissance.

  • ✗

    Packet sniffing on the target's Wi-Fi

    Why it's wrong here

    Packet sniffing is an active activity that requires local network access. It is not a method for determining IP ownership or registration details. Using a sniffer for reconnaissance is inappropriate and violates the passive nature of the information gathering phase, as it involves intercepting live traffic from the organization.

  • ✗

    Web browser history inspection

    Why it's wrong here

    Web browser history is local to the user's machine and has no relevance to identifying the ownership or location of a remote organization's network infrastructure. This is a client-side activity and does not provide any intelligence regarding the target's network, which is the primary focus of the reconnaissance phase.

About these practice questions

Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.