During external reconnaissance you collect DNS records for a target organization and find an MX record pointing to mail.example.com. You want to identify the IP addresses of other hosts in the same mail infrastructure without sending any packets directly to the target's servers. Which action best fits this passive goal?
Trap 1: Use nmap -sn 203.0.113.0/24 to discover which hosts in the mail…
A ping sweep sends ICMP or ARP probes directly to hosts in the subnet, making it an active technique that the target could log or alert on. It also requires knowing the correct subnet in advance, which the scenario has not established. While it would identify live hosts, it contradicts the explicit requirement to avoid sending packets to the target's servers, so it is the wrong choice here.
Trap 2: Run dig axfr @ns1.example.com example.com to transfer the full zone.
A zone transfer is an active query sent directly to the target's authoritative name server, which violates the passive-only constraint. Most servers also refuse AXFR from unauthorized clients, so the attempt would likely fail while still generating logs that reveal your interest. Even if it succeeded, the traffic would originate from your infrastructure and be attributable, which is precisely what passive reconnaissance avoids.
Trap 3: Perform a reverse DNS lookup against each IP in the target's…
Reverse DNS queries are sent to the name servers responsible for the in-addr.arpa zones, which for the target's prefixes are typically operated by the organization or its provider. That traffic reaches infrastructure associated with the target, so it is not passive. It also returns only PTR records, which may not correspond to live mail hosts, making it both noisy and unreliable for this purpose.
- A
Query a public passive DNS database such as SecurityTrails or VirusTotal for historical A records of example.com.
Passive DNS databases store historical resolution data collected from recursive resolvers and other sensors, so querying them reveals IP addresses and subdomains without any packet ever reaching the target's infrastructure. That directly satisfies the requirement to identify hosts while remaining passive. Historical records can also expose decommissioned or origin hosts that current DNS no longer advertises, adding reconnaissance value.
- B
Use nmap -sn 203.0.113.0/24 to discover which hosts in the mail subnet are alive.
Why it fails: A ping sweep sends ICMP or ARP probes directly to hosts in the subnet, making it an active technique that the target could log or alert on. It also requires knowing the correct subnet in advance, which the scenario has not established. While it would identify live hosts, it contradicts the explicit requirement to avoid sending packets to the target's servers, so it is the wrong choice here.
- C
Run dig axfr @ns1.example.com example.com to transfer the full zone.
Why it fails: A zone transfer is an active query sent directly to the target's authoritative name server, which violates the passive-only constraint. Most servers also refuse AXFR from unauthorized clients, so the attempt would likely fail while still generating logs that reveal your interest. Even if it succeeded, the traffic would originate from your infrastructure and be attributable, which is precisely what passive reconnaissance avoids.
- D
Perform a reverse DNS lookup against each IP in the target's announced BGP prefixes.
Why it fails: Reverse DNS queries are sent to the name servers responsible for the in-addr.arpa zones, which for the target's prefixes are typically operated by the organization or its provider. That traffic reaches infrastructure associated with the target, so it is not passive. It also returns only PTR records, which may not correspond to live mail hosts, making it both noisy and unreliable for this purpose.