Certified Ethical Hacker (CEH)

Footprinting & Reconnaissance

35 practice questions with explanations — 15 free to try

PassNova has 35 Certified Ethical Hacker (CEH) practice questions on Footprinting & Reconnaissance, each with a clear explanation. A 15-question taster is free with no sign-up; the full bank is part of PassNova Premium. Updated for 2026.

Sample questions

Footprinting & Reconnaissance: example questions & answers

2 worked examples with answers and explanations below. Try 15 Certified Ethical Hacker (CEH) questions free in the browser; the full 35-question Footprinting & Reconnaissance bank is part of PassNova Premium.

  1. During passive reconnaissance, which technique gathers information about a target WITHOUT sending any packets directly to the target's systems?

    • AEnumerating SMB shares with enum4linux against the target's file servers
    • BBanner grabbing with Netcat
    • CSearching public records, WHOIS, and search engines (OSINT)
    • DRunning an Nmap SYN scan

    Answer: Passive reconnaissance (OSINT) collects publicly available information such as WHOIS records, DNS data, and search-engine results without interacting directly with the target, leaving no trace on the target's systems.

  2. Which DNS record type must be queried to identify the mail servers responsible for a target domain?

    • APTR record
    • BA record
    • CCNAME record
    • DMX record

    Answer: The MX (Mail Exchange) record specifies the mail servers that accept email for a domain, making it the target of DNS footprinting aimed at email infrastructure.

Start practising Footprinting & Reconnaissance →