Courseiva

PEN-200 Enumeration and Reconnaissance Practice Question

Which THREE of the following are considered 'active' reconnaissance techniques, as opposed to passive techniques?

⚠ Common exam trap

Candidates often misidentify banner grabbing or simple DNS lookups as active. Active reconnaissance requires direct interaction that generates logs on the target system, unlike passive OSINT gathering.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Port scanning with Nmap.

Active reconnaissance involves direct interaction with the target system, which creates a visible footprint in server logs. Techniques like port scanning, service version detection, and directory brute-forcing are all active because they involve sending packets that the target must respond to. In contrast, passive reconnaissance uses third-party services to gather information without touching the target. Understanding this distinction is vital for maintaining the desired level of stealth throughout the reconnaissance and exploitation process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Port scanning with Nmap.

    Why this is correct

    Port scanning requires sending packets directly to the target system to determine if specific ports are open. This interaction is recorded in logs and constitutes a clear 'active' action, as the target system must process and reply to the probes, making it a highly visible reconnaissance technique.

  • ✓

    Service version detection.

    Why this is correct

    Service version detection involves sending specially crafted probes to a service to force it to disclose its version information. This direct interaction is an active process that can be detected by security systems, as it deviates from normal user traffic and actively seeks information from the application.

  • ✓

    Directory brute-forcing.

    Why this is correct

    Directory brute-forcing involves sending thousands of HTTP requests to a target server to guess hidden file or folder names. This is an inherently noisy, active technique that leaves clear evidence in web server logs, making it very likely to be detected if not performed carefully or with authorization.

  • ✗

    WHOIS lookup.

    Why it's wrong here

    A WHOIS lookup is a passive technique because you are querying a third-party registry database rather than the target host itself. This interaction does not generate traffic on the target network, making it invisible to the target's security systems and an ideal starting point for initial reconnaissance.

  • ✗

    Searching Google for public documents.

    Why it's wrong here

    Using search engines to find publicly indexed documents is a classic passive reconnaissance technique. You are querying the search engine's database, not the target's infrastructure, which means the target has no way of knowing you are researching them, ensuring complete invisibility during this phase of the engagement.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.