Footprinting and Reconnaissance Flashcards
7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Footprinting and Reconnaissance flashcards as text
What is Shodan primarily used for during the reconnaissance phase of ethical hacking?
Answer: Finding internet-connected devices and their exposed services
Shodan is a search engine that indexes internet-connected devices, revealing open ports, running services, and banners useful for identifying exposed infrastructure.
Which DNS record type maps a domain name to an IPv6 address?
Answer: AAAA record
The AAAA (quad-A) record maps a domain name to a 128-bit IPv6 address, while the A record maps to a 32-bit IPv4 address.
What security risk does an improperly configured DNS zone transfer (AXFR) present to an organization?
Answer: Exposes the entire DNS database including all internal hostnames to unauthorized parties
An unrestricted DNS zone transfer exposes all DNS records for a domain, giving attackers a complete map of the internal network infrastructure and hostnames.
What is the primary purpose of using Traceroute/Tracert during network footprinting?
Answer: Map the network path and identify intermediate routers between attacker and target
Traceroute maps the route packets take to reach a destination, revealing intermediate routers, network topology, TTL values, and potential firewall or IDS locations.
What type of sensitive organizational information can an attacker gather by analyzing a company's job postings?
Answer: Technology stack, software versions, and internal roles used by the organization
Job postings commonly list required technologies, frameworks, and software versions that reveal the organization's technical environment and potential attack vectors.
Which technique systematically queries a DNS server with a wordlist of possible names to enumerate subdomains of a target?
Answer: DNS brute-forcing
DNS brute-forcing queries DNS servers with a large list of potential subdomain names to discover all valid subdomains associated with a target domain.
What is banner grabbing used for during the reconnaissance phase of a penetration test?
Answer: Identifying software names and versions running on open ports
Banner grabbing captures the service banners returned when connecting to open ports, revealing the software type, version, and sometimes OS information.