EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesEasy

A security consultant is performing an external penetration test. They need to identify all subdomains associated with the target's primary domain (example.com) to expand the attack surface. They decide to use a technique that queries various public DNS records and search engines. Which enumeration method is being employed?

  1. ASubdomain Enumeration
  2. BActive Directory Enumeration
  3. CSMB Enumeration
  4. DSNMP Enumeration
Show answer & explanation

Correct answer: A. Subdomain Enumeration

Subdomain enumeration is the process of discovering subdomains (e.g., blog.example.com, dev.example.com) associated with a given domain. This is typically done by querying DNS records (like A, AAAA, NS, MX) and using OSINT sources like search engines or specialized tools.

Why the other options are wrong

  • B. Active Directory Enumeration targets user accounts and resources within an Active Directory environment, not public subdomains.
  • C. SMB Enumeration focuses on shared resources on Windows networks, not subdomains.
  • D. SNMP Enumeration focuses on network device information, not subdomains.

Subdomain Enumeration

The process of discovering all subdomains associated with a target domain to identify additional entry points or assets for a penetration test.

  • Expands attack surface
  • Uses various DNS record types (A, AAAA, NS, MX)
  • Leverages search engines, passive DNS, brute-forcing
  • Can reveal hidden or forgotten assets

Memory trick: Subdomains are like finding all the hidden rooms in a big house.

More Reconnaissance Techniques questions