Footprinting & Reconnaissance
35 practice questions with explanations — 15 free to try
PassNova has 35 Certified Ethical Hacker (CEH) practice questions on Footprinting & Reconnaissance, each with a clear explanation. A 15-question taster is free with no sign-up; the full bank is part of PassNova Premium. Updated for 2026.
Footprinting & Reconnaissance: example questions & answers
2 worked examples with answers and explanations below. Try 15 Certified Ethical Hacker (CEH) questions free in the browser; the full 35-question Footprinting & Reconnaissance bank is part of PassNova Premium.
During passive reconnaissance, which technique gathers information about a target WITHOUT sending any packets directly to the target's systems?
- AEnumerating SMB shares with enum4linux against the target's file servers
- BBanner grabbing with Netcat
- CSearching public records, WHOIS, and search engines (OSINT)✓
- DRunning an Nmap SYN scan
Answer: Passive reconnaissance (OSINT) collects publicly available information such as WHOIS records, DNS data, and search-engine results without interacting directly with the target, leaving no trace on the target's systems.
Which DNS record type must be queried to identify the mail servers responsible for a target domain?
- APTR record
- BA record
- CCNAME record
- DMX record✓
Answer: The MX (Mail Exchange) record specifies the mail servers that accept email for a domain, making it the target of DNS footprinting aimed at email infrastructure.