312-50 exam dumps

312-50 practice question 21 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 21

Single answer▪ Footprinting Concepts

During the reconnaissance phase of an authorized assessment, you need to identify the external IP ranges and mail servers used by a target company while minimizing direct interaction with its infrastructure. Which approach is the MOST appropriate for this footprinting objective?

  1. A

    Query public WHOIS records for netblocks and use DNS MX lookups to identify the company's mail servers

  2. B

    Run a full TCP SYN scan against the target's public IP space to discover mail servers and infer ownership

  3. C

    Send crafted phishing emails to employees and inspect the message headers in replies to identify internal mail relays

  4. D

    Perform SNMP walks against the target's edge routers to enumerate assigned subnets and SMTP hosts

Show answer and explanation

Correct answer: A

Explanation

The key phrase in the scenario is 'minimizing direct interaction with its infrastructure,' which points to passive or minimally invasive footprinting. In CEH methodology, footprinting often begins with open-source and public-record intelligence gathering before any active scanning. WHOIS records can provide ownership and allocation information for domains and IP ranges, while DNS MX records identify the authoritative mail exchangers for a domain. Together, these sources address both requirements in the scenario: identifying external IP ranges and mail servers. By contrast, SYN scanning and SNMP enumeration are active techniques that generate direct traffic to target systems. Social engineering, such as phishing, is not a standard first-line footprinting technique for this purpose and generally requires separate authorization. Relevant best-practice sources include ARIN/RIPE/APNIC WHOIS services for IP registration data and standard DNS documentation for MX record usage as defined in internet mail routing standards.

  • A. Correct.

    Correct. This is a classic footprinting approach that relies primarily on publicly available information and standard DNS queries. WHOIS data can reveal registered netblocks, autonomous system ownership, or registrar/registry details associated with the organization. DNS MX records are specifically intended to identify the mail exchangers responsible for accepting email for a domain. This method aligns with passive or minimally invasive reconnaissance and is appropriate when the goal is to minimize direct interaction with target systems.

  • B. Incorrect.

    Incorrect. A TCP SYN scan is active reconnaissance, not low-interaction footprinting. While it may help identify exposed SMTP services, it does not reliably establish ownership of IP ranges by itself and creates direct traffic to the target. The scenario explicitly asks for a method that minimizes interaction with the target infrastructure, so a full scan is not the most appropriate choice.

  • C. Incorrect.

    Incorrect. Sending phishing emails is not an appropriate footprinting technique in an authorized assessment unless explicitly scoped and approved as part of social engineering testing. It is also unnecessarily risky and intrusive for simply identifying mail servers. Although email headers can sometimes reveal routing information, this approach is not the best or most ethical first step for the stated objective.

  • D. Incorrect.

    Incorrect. SNMP walks are active enumeration and require reachable SNMP services plus valid community strings or credentials in many environments. This is not a low-interaction footprinting method, and edge routers typically do not permit anonymous SNMP queries from the internet. It is far less appropriate than using public WHOIS and DNS records.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam