
EC-CouncilCertified Penetration Testing Professional
Domain 2Objective 1
Open-Source Intelligence (OSINT) CPENT Practice Questions (Page 4)
Part of the Information Gathering and Social Engineering domain, which makes up ~9% of our current practice bank.
39questions here
8free pages
10concepts
Questions 16–20
- 16
A client is concerned about the amount of information an attacker could gather about their organization without any direct interaction. They ask you to explain what OSINT is and how it fits into a penetration test. Which statement best describes OSINT in this context?
Select an answer first - 17
You are searching for sensitive documents that may have been accidentally exposed on the target's website. You want to find PDF files that contain the word 'confidential' and are hosted on the target's domain. Which search query is most effective?
Select an answer first - 18
You are profiling a high-value target for a social engineering test. The target is very private on social media, but you have found their employer and their professional email address. You need to gather personal information that could be used to build trust. Which approach is most likely to yield useful personal information?
Select an answer first - 19
During an external assessment, you are mapping the target's internet-facing infrastructure. You have the domain name but need to discover additional subdomains and associated IP addresses. Which approach is most effective?
Select an answer first - 20
Which DNS record type is used to map a domain name to an IPv6 address?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.