312-50 exam dumps

312-50 practice question 306 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 306

Single answer▪ Footprint Web Infrastructure

During an authorized reconnaissance engagement, you need to footprint a target company's public web infrastructure without sending intrusive scans to its web servers. The client wants you to identify the technologies used behind www.example-target.com, including whether the site is fronted by a CDN/WAF and what other Internet-facing subdomains may support the web presence. Which approach is the MOST appropriate for this requirement?

  1. A

    Perform passive footprinting by reviewing DNS records, certificate transparency logs, HTTP response headers from normal browsing, and public ASN/IP ownership data

  2. B

    Run a full Nmap scan with service/version detection and NSE scripts against the target web server to enumerate middleware and hidden virtual hosts

  3. C

    Launch a web vulnerability scan with Nikto and directory brute-forcing to infer the backend framework and discover supporting applications

  4. D

    Use Metasploit auxiliary scanners to fingerprint the web stack and validate whether a WAF is present by sending crafted attack payloads

Show answer and explanation

Correct answer: A

Explanation

For CEH-level web infrastructure footprinting, the key distinction is between passive or low-impact reconnaissance and active enumeration. When a client explicitly restricts intrusive scans, the assessor should prioritize passive sources and ordinary interactions: DNS intelligence, WHOIS or RDAP and ASN ownership data, certificate transparency logs, search engine results, and normal HTTP/HTTPS requests to inspect response headers and TLS certificate metadata. These methods help identify hosting providers, CDN/WAF usage, related subdomains, and technology indicators without aggressive probing. In practice, certificate transparency sources such as publicly logged TLS certificates often reveal additional web-facing hostnames, while DNS and CNAME chains can indicate providers like CDN or reverse-proxy services. Header review and TLS certificate inspection can further suggest load balancers, cache layers, and web servers. This aligns with common reconnaissance best practices and the CEH objective of footprinting web infrastructure before moving into more active phases.

  • A. Correct.

    Correct. This is the best fit for a low-impact, largely passive web infrastructure footprinting requirement. Reviewing DNS data can reveal records such as CNAMEs pointing to CDN providers, MX/TXT/SPF details, and related subdomains. Certificate transparency logs can expose additional hostnames covered by issued TLS certificates. Standard HTTP response headers obtained through ordinary browsing may disclose server, cache, CDN, or security gateway information without intrusive probing. ASN and IP ownership lookups help attribute hosting, CDN, or cloud providers. These are common, practical techniques for footprinting web infrastructure while minimizing direct interaction with the target.

  • B. Incorrect.

    Incorrect. Nmap service/version detection and NSE enumeration are active scanning techniques. While useful in later phases of an assessment, they do not meet the stated requirement to avoid intrusive scans. They may also trigger alerts on perimeter devices, especially when used to detect middleware, virtual hosts, or exposed services.

  • C. Incorrect.

    Incorrect. Nikto and directory brute-forcing are active enumeration methods that generate numerous requests and are more likely to be considered intrusive. They are appropriate for deeper web assessment, but not for a constrained footprinting phase where the goal is to gather infrastructure intelligence with minimal impact.

  • D. Incorrect.

    Incorrect. Metasploit auxiliary scanners and crafted payloads are active probing methods. Sending attack-like requests specifically to detect a WAF is not aligned with the client's requirement to avoid intrusive scans. This approach moves beyond passive footprinting into active testing.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam