Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 2Objective 2

Whois, DNS and Email Footprinting CEH Practice Questions (Page 9)

Part of the Reconnaissance Techniques domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~13–22 in this domain), expect 2–3 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
11concepts

Questions 41–45

  1. 41foundation · easy

    In a Whois record, which field typically indicates the organization or individual that owns the domain?

    Select an answer first
  2. 42expert · hard

    You are investigating a spear-phishing email that was sent to multiple employees. The email contains an embedded image that is loaded from an external URL. The image URL is unique for each recipient. You notice that the email was opened by several recipients, and the external server logged their IP addresses. What is the most likely purpose of using unique image URLs?

    Select an answer first
  3. 43application · medium

    You have discovered an IP address (203.0.113.45) during a penetration test. You want to find out which hostname resolves to this IP address to identify the server's role. Which DNS query should you perform?

    Select an answer first
  4. 44application · medium

    A security analyst is reviewing a Whois record for a domain and sees the following fields: Registrar: Example Registrar Inc. Creation Date: 2015-03-15 Expiration Date: 2025-03-15 Name Servers: ns1.examplehost.com, ns2.examplehost.com Registrant Organization: Example Corp. What can the analyst infer from this record?

    Select an answer first
  5. 45expert · hard

    A penetration tester is attempting to enumerate all DNS records for a target domain. The tester has identified the authoritative name server and attempts a zone transfer, but the server does not respond to the AXFR request. The tester then tries a different approach: querying for common subdomains (e.g., www, mail, ftp) using 'dig'. This approach is known as brute-force subdomain enumeration. Why might this approach be more successful than a zone transfer?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CEH

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.