312-50 exam dumps

312-50 practice question 42 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 42

Single answer▪ Whois Footprinting

During the reconnaissance phase of an authorized assessment, you need to perform Whois footprinting on examplecorp.com to identify external points of contact and infrastructure management clues without directly interacting with the target's hosts. Which Whois finding would be the most actionable for expanding your passive reconnaissance while staying within the scope of Whois-based footprinting?

  1. A

    The domain's registrar, registration dates, and the listed registrant/admin/tech contact email addresses

  2. B

    The list of all open TCP ports on examplecorp.com's public web server

  3. C

    The exact operating system version running on the authoritative DNS server

  4. D

    The full set of internal hostnames used on ExampleCorp's private network

Show answer and explanation

Correct answer: A

Explanation

Whois footprinting is a passive reconnaissance technique used to gather publicly available registration information about a domain or IP allocation. In practice, useful Whois data may include the registrar, registration timeline, name servers, and contact or abuse-reporting details when not masked by privacy services or redacted under registry rules. These findings help an ethical hacker identify third-party providers, likely infrastructure owners, and administrative contacts for subsequent authorized steps. By contrast, information such as open ports, OS versions, or internal hostnames requires active enumeration or other data sources and is not part of standard Whois output. This aligns with common CEH reconnaissance methodology and standard registry/registrar Whois or RDAP usage, where the focus is on publicly registered metadata rather than live host interrogation.

  • A. Correct.

    Correct. Whois records commonly provide domain registration metadata such as the registrar, creation and expiration dates, name servers, and sometimes registrant, administrative, and technical contact details, depending on registry policy and privacy protections. In an authorized CEH-style reconnaissance scenario, these details are highly actionable because they can reveal points of contact, outsourced service providers, and name server information that support further passive enumeration.

  • B. Incorrect.

    Incorrect. Open TCP ports are not provided by Whois. Determining open ports requires active scanning techniques such as Nmap or similar tools, which go beyond passive Whois footprinting and directly probe target systems.

  • C. Incorrect.

    Incorrect. Whois does not disclose the exact operating system version of a DNS server. That type of detail would typically require active fingerprinting, banner grabbing, or vulnerability assessment techniques, not domain registration lookups.

  • D. Incorrect.

    Incorrect. Internal hostnames on a private network are not exposed through standard Whois records. A candidate might choose this if they confuse Whois with internal asset inventories or DNS zone transfer data, but Whois is limited to domain registration and related public registry information.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam