Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilEthical Hacking Essentials

Domain 3Objective 1

Reconnaissance, Footprinting, and OSINT Techniques EHE Practice Questions (Page 7)

Part of the Ethical Hacking Methodology domain, which makes up ~12% of our current practice bank.

42questions here
9free pages
8concepts

Questions 31–35

  1. 31application · medium

    A threat intelligence analyst is tasked with assessing the risk of a targeted phishing campaign against a specific company. The analyst has collected the following OSINT: employee names and job titles from LinkedIn, the company's email format (firstname.lastname@company.com), and the technologies listed in job postings (e.g., Microsoft 365, Salesforce). Which analysis best applies this OSINT to identify potential attack vectors?

    Select an answer first
  2. 32expert · hard

    A security analyst is performing OSINT on a target organization. The analyst has found that the organization's employees use a common password pattern (e.g., Season+Year) and that the organization recently suffered a data breach that exposed hashed passwords. The analyst also found a public GitHub repository where a developer accidentally committed a file containing internal API keys. Which OSINT finding is most directly actionable for gaining unauthorized access?

    Select an answer first
  3. 33application · medium

    An OSINT analyst is building a profile of a target organization for a red team exercise. The analyst has found the organization's domain registration details, employee email addresses, and a list of technologies mentioned in job postings. The analyst now needs to find any publicly exposed documents that might contain metadata such as usernames or internal paths. Which OSINT technique is most appropriate for this task?

    Select an answer first
  4. 34application · medium

    A security analyst is footprinting a target organization. The analyst wants to gather information about the organization's network infrastructure, including DNS servers and mail servers, without directly querying the target's systems. Which OSINT tool or source is most appropriate?

    Select an answer first
  5. 35foundation · easy

    What is a common risk associated with active reconnaissance?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.