312-50 exam dumps

312-50 practice question 40 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 40

Single answer▪ Whois Footprinting

During a permitted reconnaissance phase, you are asked to identify the most reliable administrative contact information and registrar details for a client-owned domain, apexfinbank.com, before expanding into DNS and subdomain enumeration. The domain uses privacy protection, so the registrant name and email are masked. Which action would best help you obtain accurate domain registration metadata while staying within the scope of Whois footprinting?

  1. A

    Query the domain's Whois record through the appropriate registrar or registry Whois/RDAP service to review registrar, nameserver, status, registration dates, and any available abuse or technical contact fields

  2. B

    Perform a DNS zone transfer (AXFR) against the authoritative name servers because zone transfer responses include the registrar's administrative contact and masked registrant identity

  3. C

    Use traceroute to the web server hosting apexfinbank.com because the route path reveals the domain's registrar and current domain status codes

  4. D

    Run a network vulnerability scan against the public IP range because service banners commonly expose domain registration contacts when privacy protection is enabled

Show answer and explanation

Correct answer: A

Explanation

The best answer is to query the domain's authoritative registration data through Whois or, increasingly, RDAP. In real-world CEH-style reconnaissance, Whois footprinting is used early to gather domain ownership and management details such as registrar name, domain status, creation and expiration dates, and nameserver assignments. Privacy or proxy registration often masks the registrant's personal identity, but useful metadata usually remains available for pivoting into later phases such as DNS investigation and external attack surface mapping. By contrast, DNS zone transfers, traceroute, and vulnerability scanning are different reconnaissance or enumeration activities and are not substitutes for registration lookups. As a best-practice reference, ICANN's Registration Data Access Protocol (RDAP) is the modern standardized mechanism replacing many traditional Whois functions, and registrar or registry-operated Whois/RDAP services are the authoritative sources for this type of metadata.

  • A. Correct.

    Correct. Whois footprinting is specifically intended to retrieve domain registration metadata such as the registrar, registry dates, nameservers, and domain status values. Modern lookups are often provided through RDAP as well as traditional Whois. Even when privacy protection masks registrant details, registrar information, nameservers, registration and expiration dates, and sometimes abuse or technical contact channels may still be available. This is the most appropriate and scoped first step for gathering domain ownership and management metadata.

  • B. Incorrect.

    Incorrect. A DNS zone transfer is a DNS enumeration technique, not a Whois footprinting method. AXFR, if misconfigured and allowed, may reveal hostnames and DNS records, but it does not serve as the proper source for registrar metadata or registrant contact information. This option reflects a common misconception that all domain-related information comes from DNS rather than registration databases.

  • C. Incorrect.

    Incorrect. Traceroute can help identify network paths and intermediate hops between the tester and a target system, but it does not reveal registrar information, domain registration dates, or Whois status codes. Someone might choose this if they confuse network path discovery with domain registration reconnaissance.

  • D. Incorrect.

    Incorrect. Vulnerability scanning is active enumeration of hosts and services, not Whois footprinting. Service banners may identify software versions or sometimes hostnames, but they do not provide authoritative domain registration metadata. This option is outside the stated goal of collecting registrar and contact information through registration records.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam