312-50 exam dumps

312-50 practice question 19 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 19

Single answer▪ Footprinting Concepts

During a sanctioned pre-engagement assessment, you are asked to collect as much information as possible about a target company without sending any packets directly to its network. The client specifically wants to know which Internet-facing hosts likely belong to the organization and whether any employee information could support later social-engineering risk analysis. Which approach best meets these requirements while staying within passive footprinting boundaries?

  1. A

    Query public WHOIS records, examine DNS data from public sources, review certificate transparency logs, and correlate employee details from the company's website and professional networking sites

  2. B

    Run an Nmap SYN scan against the company's public IP ranges, perform banner grabbing on exposed services, and enumerate SMB shares for user names

  3. C

    Use traceroute and ping sweeps to identify live hosts, then fingerprint operating systems with TCP/IP stack analysis

  4. D

    Launch a DNS zone transfer request against the authoritative name server and use SNMP queries against edge devices to map the environment

Show answer and explanation

Correct answer: A

Explanation

The key distinction in this scenario is passive versus active footprinting. Passive footprinting gathers intelligence from publicly available or third-party sources without directly touching the target's network. Typical passive sources include WHOIS/RDAP records, public DNS information, search engines, archived web content, social media, job postings, certificate transparency logs, and business registries. By contrast, techniques such as Nmap scans, ping sweeps, traceroute, banner grabbing, zone transfer attempts, and SNMP enumeration are active because they generate traffic to target systems. In real-world engagements, passive footprinting is often used early to define scope, identify likely assets, and reduce noise before any active reconnaissance begins. Relevant references and best-practice sources include ICANN WHOIS/RDAP guidance for registration data, public Certificate Transparency ecosystems described in RFC 6962, and general reconnaissance methodology used in ethical hacking frameworks that separate OSINT/passive information gathering from active scanning and enumeration.

  • A. Correct.

    Correct. This is a passive footprinting approach because it relies on publicly available information and third-party data sources rather than directly interacting with the target's systems. WHOIS can reveal domain registration and network ownership details, public DNS data can identify likely hostnames, certificate transparency logs often expose subdomains associated with issued TLS certificates, and public employee information from company pages or professional networking platforms can support social-engineering risk analysis. This aligns well with the scenario's requirement to avoid sending packets to the target network.

  • B. Incorrect.

    Incorrect. Nmap SYN scans, banner grabbing, and SMB enumeration are active reconnaissance techniques because they directly probe the target's systems and services. Although these methods are useful in later phases of an assessment, they violate the explicit requirement to avoid sending packets to the target network. A candidate might choose this option because it is effective for discovering Internet-facing hosts, but it is not passive footprinting.

  • C. Incorrect.

    Incorrect. Traceroute, ping sweeps, and TCP/IP stack fingerprinting are also active methods. Even though they are common host discovery and fingerprinting techniques, they involve direct network interaction with the target environment. The misconception here is assuming low-impact probing is the same as passive reconnaissance; in CEH terms, it is still active footprinting or scanning.

  • D. Incorrect.

    Incorrect. A DNS zone transfer request and SNMP queries both involve direct interaction with target-controlled infrastructure and therefore are not passive. Additionally, a zone transfer is only successful when misconfigured and should not be assumed available from public servers. This option is plausible because DNS and SNMP can reveal valuable infrastructure details, but it does not satisfy the passive-only constraint.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam