Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilEthical Hacking Essentials

Domain 3Objective 1

Reconnaissance, Footprinting, and OSINT Techniques EHE Practice Questions (Page 4)

Part of the Ethical Hacking Methodology domain, which makes up ~12% of our current practice bank.

42questions here
9free pages
8concepts

Questions 16–20

  1. 16application · medium

    A security analyst is performing passive reconnaissance on a target organization. The analyst wants to identify the organization's subdomains and internal network structure without directly querying the target's DNS servers. Which OSINT source is most effective for this purpose?

    Select an answer first
  2. 17expert · hard

    A red team operator is tasked with gaining initial access to a target organization. The operator has a limited budget and cannot afford commercial threat intelligence feeds. The operator needs to identify valid employee credentials or at least a list of potential usernames for a password spraying attack. The organization uses Microsoft 365 and has a standard email format of firstname.lastname@company.com. Which OSINT approach is most effective and cost-efficient?

    Select an answer first
  3. 18foundation · easy

    What is a key characteristic of passive reconnaissance?

    Select an answer first
  4. 19foundation · easy

    What is the final step in the footprinting process?

    Select an answer first
  5. 20foundation · easy

    Which statement correctly distinguishes passive reconnaissance from active reconnaissance?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.