312-50 exam dumps

312-50 practice question 36 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 36

Single answer▪ Website Footprinting

During a sanctioned reconnaissance phase, you are asked to gather information about a target organization's public web presence without directly interacting with the web server in a way that could trigger rate limits or alerts. You need to identify historical technologies, exposed directories, and previous page content associated with www.examplecorp.com. Which action is the MOST appropriate for website footprinting under these constraints?

  1. A

    Use Google advanced search operators and the Internet Archive's Wayback Machine to review indexed content, cached references, and historical versions of the site

  2. B

    Run a full authenticated vulnerability scan against www.examplecorp.com to enumerate web application components and hidden directories

  3. C

    Launch a directory brute-force attack with a wordlist against www.examplecorp.com to discover unlinked resources

  4. D

    Perform an aggressive Nmap scan with version detection and NSE scripts against the web server to fingerprint the web stack

Show answer and explanation

Correct answer: A

Explanation

The key requirement in this scenario is to perform website footprinting with minimal direct interaction. In CEH-style reconnaissance, this points to passive information gathering techniques such as search engine reconnaissance, review of search engine caches, and historical website analysis using archive services. Google dorking can identify publicly indexed documents, login pages, backup files, and directory listings that were exposed to crawlers. The Internet Archive's Wayback Machine is valuable for discovering older site structures, deprecated endpoints, and historical technologies that may no longer be obvious on the current site. These methods align with standard passive reconnaissance practices and reduce the chance of detection because the target server is not being directly scanned or fuzzed by the tester. By contrast, vulnerability scans, directory brute-forcing, and aggressive Nmap scans are active techniques and are more likely to generate logs, trigger web application firewalls, or violate stealth requirements. Relevant references include the Internet Archive Wayback Machine for historical site snapshots and common search-engine reconnaissance practices documented in ethical hacking and OSINT methodologies.

  • A. Correct.

    Correct. This approach relies on third-party sources rather than direct probing of the target, making it ideal when the goal is to minimize interaction with the web server. Google advanced operators can reveal indexed files, exposed pages, and references to subdomains or directories, while the Internet Archive's Wayback Machine can show historical page content, older technologies, deprecated paths, and previously exposed resources. This is a classic website footprinting technique used during passive reconnaissance.

  • B. Incorrect.

    Incorrect. A full authenticated vulnerability scan is active testing, not passive website footprinting. It requires direct interaction with the target and can generate significant traffic, trigger alerts, and exceed the stated constraints. It is useful later in an assessment but is not the best choice here.

  • C. Incorrect.

    Incorrect. Directory brute-forcing is an active enumeration technique that sends many requests to the target server in an attempt to discover hidden content. Although it can find exposed directories, it directly conflicts with the requirement to avoid interactions likely to trigger rate limits or monitoring.

  • D. Incorrect.

    Incorrect. An aggressive Nmap scan with service/version detection and NSE scripts is active network and service enumeration. While it may help fingerprint the web server and related services, it is not suitable when the objective is passive website footprinting with minimal direct contact.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam