312-50 exam dumps

312-50 practice question 53 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 53

Single answer▪ Footprinting Tools

During a rules-of-engagement approved reconnaissance phase, you need to identify the autonomous system number (ASN), netblocks, and upstream provider information for a target organization before scoping external attack surface testing. The client wants this done using passive footprinting so you do not directly probe their infrastructure. Which tool is the most appropriate for this task?

  1. A

    WHOIS

  2. B

    Nmap

  3. C

    hping3

  4. D

    netcat

Show answer and explanation

Correct answer: A

Explanation

This scenario focuses on passive footprinting, which means collecting information without directly sending probes to the target's systems. For identifying an organization's ASN, IP ranges, and provider or allocation details, WHOIS is the best fit. In practice, ethical hackers often combine domain WHOIS and RIR WHOIS lookups to map ownership and public address space before any active testing begins. This aligns with common reconnaissance methodology in CEH: start with passive intelligence sources before moving to active enumeration. Relevant references include ICANN WHOIS/RDAP services and Regional Internet Registry databases such as ARIN, RIPE NCC, APNIC, LACNIC, and AFRINIC, which publish allocation and registration information used during footprinting.

  • A. Correct.

    Correct. WHOIS is a passive footprinting resource commonly used to gather domain registration details, registrar data, contact information, and, importantly for many organizations, ASN and IP allocation information through regional internet registry records such as ARIN, RIPE, APNIC, LACNIC, or AFRINIC. This makes it suitable for identifying netblocks and upstream ownership without directly interacting with the target's hosts.

  • B. Incorrect.

    Incorrect. Nmap is an active reconnaissance and scanning tool used for host discovery, port scanning, service detection, OS fingerprinting, and related tasks. Although very useful later in an assessment, it is not passive and would directly probe the target infrastructure, which violates the scenario requirement.

  • C. Incorrect.

    Incorrect. hping3 is an active packet-crafting and network testing tool often used for firewall testing, TCP/IP stack analysis, traceroute-like functions, and custom packet generation. It is not intended for passive collection of ASN ownership or registration-based netblock intelligence.

  • D. Incorrect.

    Incorrect. netcat is a general-purpose networking utility for reading from and writing to network connections. It can be used for banner grabbing, port interaction, and troubleshooting, but it does not provide passive ownership or registry intelligence such as ASN and allocation records.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam