312-50 exam dumps

312-50 practice question 22 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 22

Single answer▪ Footprinting Methodology

You are performing the reconnaissance phase of an authorized assessment against a company named Acme Financial. The rules of engagement state that you must begin with passive footprinting only and avoid sending traffic directly to Acme-owned hosts until the client approves active scanning. Your goal is to identify internet-facing assets and likely email formats for later testing. Which action is the MOST appropriate to perform first?

  1. A

    Query public WHOIS records, review registrar and ASN information, and inspect certificate transparency logs and search engine results for Acme-related domains and subdomains

  2. B

    Run an Nmap SYN scan against Acme's public IP ranges to identify live hosts and open ports without completing TCP handshakes

  3. C

    Use a DNS zone transfer (AXFR) request against Acme's authoritative name servers to enumerate internal and external hostnames

  4. D

    Send crafted phishing emails to several Acme employees to confirm the organization's email address format

Show answer and explanation

Correct answer: A

Explanation

In CEH reconnaissance, footprinting should start with the least intrusive methods, especially when rules of engagement restrict testing to passive activities. Passive footprinting uses publicly available sources such as WHOIS/RDAP records, regional internet registry and ASN data, search engines, cached pages, public job postings, social media, certificate transparency logs, and public DNS records obtained through third-party sources. These methods help identify domains, subdomains, providers, business relationships, and probable email naming conventions without touching the target infrastructure directly. By contrast, Nmap scans and DNS zone transfer attempts are active enumeration techniques because they send traffic to the target's systems. Social engineering actions such as phishing are even more sensitive and require explicit approval. Best practice is to begin with open-source intelligence and only move to active enumeration after authorization. Relevant references include Nmap documentation for the active nature of SYN scanning, DNS operational guidance on AXFR behavior, and certificate transparency resources that expose publicly logged TLS certificates and associated hostnames.

  • A. Correct.

    Correct. This is passive footprinting and aligns with the rules of engagement. Public WHOIS data, registrar details, ASN ownership, certificate transparency logs, and search engine indexing can reveal domains, subdomains, hosting providers, and naming patterns without directly probing Acme systems. This is an appropriate first step in a CEH-style footprinting methodology because it builds a target profile before any active interaction.

  • B. Incorrect.

    Incorrect. An Nmap SYN scan is active reconnaissance because it sends packets directly to target systems. Even though a SYN scan may avoid completing the full TCP handshake, it still interacts with Acme-owned hosts and would violate a passive-only requirement.

  • C. Incorrect.

    Incorrect. Attempting a DNS zone transfer is an active technique. It directly queries the target's authoritative name server and tests for a specific misconfiguration. While AXFR can be valuable during enumeration, it is not appropriate when only passive footprinting is permitted.

  • D. Incorrect.

    Incorrect. Sending phishing emails is neither passive footprinting nor an appropriate first reconnaissance action. It actively engages users, creates operational and legal risk, and typically requires explicit authorization under social engineering rules of engagement. Email format discovery should begin with passive methods such as reviewing public contacts, press releases, LinkedIn profiles, or breached-data monitoring where contractually allowed.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam