Skip to content
ScopefileGet the app

Module 2Domain 2 of 9Reconnaissance Techniques

Footprinting and reconnaissance

Footprinting is the first phase of an engagement: gathering information about a target, mostly before touching it. Module 2 splits that work into passive collection, which never interacts with the target, and active collection, which does, and the line between them is the idea the whole module turns on.

Exam
312-50
Domain
2 of 9
Domain weight
17%
This file
~6%
Targets
17

Where footprinting sits

Footprinting opens the Reconnaissance Techniques domain, the second-heaviest on the exam at 17% under EC-Council's blueprint v5.0, behind Network and Perimeter Hacking at 24% (as of Oct 11, 2026). The module sets a mental model that scanning networks and enumeration both reuse: collect quietly first, then probe.

The blueprint lists the sources: search engines, web services, social networking, WHOIS and RDAP, DNS, email, and the tools and countermeasures around them. Across all of it, one distinction organizes the module, whether an activity touches the target or stays on third-party records. It builds on the overview in Module 1, where footprinting is named as the first of the five phases.

Passive versus active footprinting

The distinction that organizes Module 2.
TraitPassiveActive
Touches the target? (differs)No, only third-party and public recordsYes, sends traffic to the target directly
Detection risk (differs)Very low; nothing to log on the targetHigher; the target can see and record it
Typical sources (differs)Search engines, social media, registries, archivesQuerying the target's own servers and services
What it yields (differs)Breadth and context, rarely live confirmationDirect confirmation of what is live now
Both need authorizationYesYes

Tinted rows marked ≠: the two differ.

Which source reveals what

Match a gathered fact back to its public source, and name the countermeasure.
SourceWhat it can exposeDefender's countermeasure
WHOIS and RDAP registration recordsRegistrant and registrar details and registration dates for a domainRegistration privacy and generic role contacts instead of named staff
DNS recordsHosts and services that sketch the external footprintSplit-horizon DNS; keep internal names off public zones
Search engines and social mediaStaff names, technologies in use, and detail leaked in posts or talksA disclosure policy and review of what employees publish
Website and page metadataTechnologies, staff names and structure visible in page source and document metadataStrip metadata and comments before publishing
Certificate Transparency and passive DNSCertificates issued for a domain and the subdomains they nameInventory every certificate issued; retire stale records

The recon vocabulary

WHOIS vs RDAP
Two ways to query domain registration. RDAP returns the same ownership data in a structured, machine-readable form, which makes it the easier record to parse.
DNS zone transfer
A bulk copy of a zone's records. A server that allows it to anyone hands over its host inventory, which is why it is a misconfiguration to close.
Certificate Transparency
Public logs of issued TLS certificates. They are queried without ever contacting the target, so they count as passive.
OSINT
Open-source intelligence: assembling a picture from publicly available sources. Usually passive, though reading the target's own site shades into active.
Google dorking
Using advanced search operators to narrow public results by file type, site or page title. Passive, because the target's servers are never queried.

Sort the recon activity

Each item describes a gathering activity or a source. Decide passive or active, name the source, or name the countermeasure, with a note on every option.

Answered 0/17Hits 0

T-01

A security analyst conducts footprinting entirely through public WHOIS records and internet routing registries. What specific category of organizational intelligence is predominantly gathered using these specific public sources?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: WHOIS and routing registries reveal registrant and administrative contacts, IP allocations and autonomous system routing boundaries.
  2. BInternal topology and Active Directory structure are not published in public registries and require internal access or leaks to learn.
  3. CWorkstation operating system versions cannot be learned from public registries; they require scanning or internal data.
  4. DHidden directories and admin portals are found by probing web applications, not by reading registry records.
T-02

An analyst reviews passive DNS logs for a subdomain. The A record recently shifted from a corporate-owned Autonomous System Number (ASN) to a consumer broadband ASN. What does this shift MOST likely indicate?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA zone transfer to a secondary provider would not move the host's IP address onto residential broadband space.
  2. BReverse DNS pointer updates do not change which ASN the forward A record resolves into.
  3. CCorrect: a host moving onto consumer broadband space most plausibly reflects unsanctioned shadow IT, though possible compromise or takeover should be investigated.
  4. DContent delivery networks run on their own commercial ASNs, not on consumer broadband ranges.
T-03

In passive reconnaissance, which method would provide the most comprehensive details about a target's network infrastructure without triggering any alerts on the target systems?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: search engines, social media and public records are passive sources that never touch the target, so they cannot trigger its alerts.
  2. BPing sweeps send packets directly to the target's addresses, which is active scanning that monitoring can detect.
  3. CSniffing requires network access to the target's traffic, which is not passive public-source reconnaissance.
  4. DPort scans actively probe the target's hosts and are a classic trigger for intrusion detection alerts.
T-04

A security analyst examines Certificate Transparency logs and finds a single certificate where the Subject Alternative Name (SAN) entries include both secure-prod.example.com and test-dev.example.com. Which vulnerability does this provisioning MOST likely introduce?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACertificate SAN entries say nothing about whether name servers allow zone transfers.
  2. BOrigin IP leakage around a WAF is found through DNS history or misconfigured records, not shown by shared SAN entries.
  3. CCertificate Transparency logs list hostnames, not internal address translation mappings.
  4. DCorrect: one certificate for production and dev hostnames implies shared keys or hosting, so a compromise of the weaker dev environment can reach production.
T-05

During reconnaissance, an analyst identifies an A record pointing to an IP address that returns an HTTP response header of Server: cloudflare. Why is running an aggressive Nmap port scan against this specific IP address ineffective?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACloudflare does not require special authorization payloads in TCP packets; it simply proxies only the services it fronts.
  2. BCorrect: the address belongs to Cloudflare's reverse proxy edge, so scanning it reveals the provider's infrastructure, not the organization's origin servers.
  3. CDNS resolution is unrelated here; the problem is that the resolved address is a proxy, not the origin.
  4. DFast-flux is a malicious technique of rapidly rotating IPs, whereas a CDN edge address is a legitimate, stable proxy.
T-06

During an external reconnaissance engagement, an analyst must verify whether several discovered IP addresses genuinely belong to the target organization. Which combination of passive indicators provides the most reliable proof of current asset ownership?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AHistorical passive DNS shows past mappings, which may be stale and do not prove current ownership.
  2. BCorrect: a TLS certificate issued to the organization served from an address inside the organization's own registered ASN strongly supports current ownership.
  3. CRedacted registry contacts are often incomplete or outdated, so they offer weak proof of ownership.
  4. DA CDN edge node is shared infrastructure run by the provider, so its response does not prove the organization owns the address.
T-07

Which of the following search operators would be used in Google dorking to find specific file types on a target domain?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ARestricts results to pages containing a given word in the body text, which helps find content but does not filter by document format.
  2. BMatches a string inside the URL path, useful for spotting admin or login paths but not a reliable way to target file formats.
  3. CReturned Google's stored copy of a page; Google retired this operator in 2024, and it never filtered by file type.
  4. DCorrect: filetype: limits results to a document extension such as PDF, XLSX or DOCX, which is why defenders audit what their domain exposes this way.
T-08

An analyst receives an RDAP JSON response for a privacy-protected domain. To pivot the investigation and identify the administrative organization managing the domain's authoritative routing, which structured field is the BEST lead?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AAn update timestamp shows when the record last changed, which adds timeline context but names no organization behind the domain's infrastructure.
  2. BCorrect: delegated name servers survive privacy redaction and point to the DNS operator actually serving the domain, a solid pivot for related infrastructure.
  3. CThe registrar abuse contact is a generic reporting channel for the registrar, not the party that operates the domain's DNS infrastructure.
  4. DAn RIR allocation date describes when an IP block was assigned, which is network-level history rather than a lead on who runs the domain.
T-09

What is the term for the technique of collecting email addresses and usernames from public sources related to an organization?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. APhishing is the delivery of deceptive messages to targets; it may use harvested addresses but is not the act of collecting them.
  2. BSpoofing forges the sender address of a message so it appears trusted, which is impersonation rather than data collection.
  3. CCorrect: email harvesting gathers addresses and usernames from websites, documents, social media and breach data, feeding later phishing or password attacks.
  4. DEnumeration usually means actively querying a service, such as SMTP VRFY, to confirm accounts exist, not scraping public sources passively.
T-10

A penetration tester is mapping a target's external perimeter. Which reconnaissance workflow correctly sequences passive enumeration techniques to discover new subdomains, validate their historical IP changes, and identify potential cloud caching protections?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AZone transfers and port scans touch the target's own servers directly, so this sequence is active probing rather than passive enumeration.
  2. BCorrect: certificate transparency logs expose new subdomains, passive DNS shows their IP history, and response headers reveal CDN or caching layers in front.
  3. CWHOIS and RIR data help scope ownership, but automated vulnerability sweeps are active and do not validate subdomain IP history.
  4. DInternal IP addresses and deep packet inspection are unavailable to an outside party doing passive perimeter mapping, so this workflow is unrealistic.
T-11

During an online webinar, a publicly traded company shares details about their upcoming projects, operational methods, and future goals. What type of sensitive and proprietary information could an attacker collect through footprinting in this instance?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AOffice addresses are usually public and are not what a webinar on projects and goals would reveal.
  2. BA listed company already publishes revenue in its filings, so it is neither proprietary nor specific to this webinar.
  3. CAn executive's personal interests come from social media profiling, not from a corporate presentation about operations.
  4. DCorrect: upcoming projects and strategic goals shared publicly are sensitive business intelligence that attackers can use for pretexts or competitive targeting.
T-12

What type of records would you examine to find detailed information about the mail servers used by a target organization?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: MX records name the hosts that accept mail for a domain and their priority, revealing the organization's mail infrastructure or provider.
  2. BCNAME records alias one hostname to another and do not specifically identify the servers handling email.
  3. CA records map a hostname to an IPv4 address; they locate a host but do not mark which hosts handle mail.
  4. DPTR records perform reverse lookups from an IP address to a hostname rather than listing a domain's mail servers.
T-13

During reconnaissance, what information can be gathered from examining a website's robots.txt file?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AConnection strings live in server-side configuration files and never belong in robots.txt, which is a public crawler instruction file.
  2. BServer-side code is executed on the server and is not exposed through robots.txt, which only lists URL paths.
  3. CCredentials should never appear in robots.txt; the file simply tells crawlers which paths to skip.
  4. DCorrect: Disallow entries list paths the owner prefers search engines skip, which can unintentionally advertise admin or staging areas to anyone reading it.
T-14

An assessment team relies exclusively on Certificate Transparency (CT) logs and passive DNS archives to enumerate a target's infrastructure. What represents the most significant limitation of this methodology?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. APassive DNS archives are third-party historical datasets and do not selectively block queries from penetration testing ranges, so this is not the main limitation.
  2. BCertificate Transparency logs are public and searchable through many aggregators, so rate limiting does not prevent comprehensive collection of domain data.
  3. CCorrect: these sources only record publicly trusted certificates and resolutions seen by sensors, so internal hosts with private certificates never appear in them.
  4. DCertificate Transparency logs are append-only, so expired or revoked certificates remain listed rather than being purged.
T-15

An analyst reviews passive DNS data for suspicious.xyz and observes 47 distinct IP addresses across 12 different ASNs within a 6-hour window. Which inference is MOST supported by this evidence?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: dozens of IPs across many ASNs within hours, often with short TTLs, is the classic fast-flux pattern used to keep malicious hosting resilient.
  2. BA DDoS affects traffic volume toward the domain; it does not make the domain's DNS answers rotate across dozens of networks.
  3. CPopular services do use many IPs, but they typically sit within a few known provider ASNs, not a dozen unrelated ones in six hours.
  4. DLegitimate load balancing and CDNs rotate within stable, recognizable provider networks rather than churning through many unrelated ASNs this quickly.
T-16

Which of the following is NOT a reconnaissance countermeasure?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AEncrypting sensitive data limits what an attacker gains from collected information, so it does support a defensive posture.
  2. BPatching reduces what version and service information can be turned into exploitable findings, making it a valid defensive measure.
  3. CCorrect: exposing sensitive resources publicly does the opposite of a countermeasure, handing reconnaissance easy information and access.
  4. DAn IDS can detect scanning and probing activity, giving defenders early warning of reconnaissance.
T-17

Which open source framework, written in Python, aggregates data from different social media platforms, and performs extensive web scraping to gather information on a target?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AThe Social Engineering Framework is a knowledge resource and toolkit for social engineering, not a Python OSINT aggregator for social media.
  2. BShodan is a search engine indexing internet-connected devices and banners, not a framework that scrapes social media profiles.
  3. CCorrect: OSRFramework is a Python collection of tools that checks usernames and profiles across many platforms and scrapes public data about a target.
  4. DNetcraft reports on websites, hosting and site technologies, and is not an open-source social media aggregation framework.

Common footprinting mix-ups

Where does footprinting stop and scanning start?

Footprinting collects context without probing live services; scanning actively sends packets to discover hosts, ports and services. That boundary is the passive-active line again.

Is reading public records about a company legal recon?

On an authorized engagement with public sources, yes, because passive footprinting touches no target system. The scope agreement still defines what you may do with the findings.

Sources