EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesEasy
A security analyst is investigating suspicious network activity originating from an unknown IP address. They want to identify the country and the Internet Service Provider (ISP) associated with this IP address to gather initial intelligence. Which of the following tools or techniques would be most effective for this purpose?
- ADNS zone transfer
- BNmap port scanning
- CTraceroute
- DWHOIS lookup
Show answer & explanationAnswer & explanation
Correct answer: D. WHOIS lookup
A WHOIS lookup is a query protocol used to retrieve registration information about a domain name or an IP address, including the registrant's contact information, registrar, creation/expiration dates, and often the associated ISP and geographical location (country). This directly answers the need to identify the country and ISP.
Why the other options are wrong
- A. DNS zone transfer enumerates all DNS records for a domain, but not the registration details of an arbitrary IP address.
- B. Nmap port scanning identifies open ports on a host, not its geographical or ISP registration details.
- C. Traceroute maps the network path to a host, not its registration details.
WHOIS Lookup
A query and response protocol widely used for querying databases that store the registered users or assignees of an Internet resource, such as a domain name, an IP address block, or an autonomous system.
- Provides registration details (registrant, ISP, contact info).
- Useful for IP addresses and domain names.
- Helps in initial intelligence gathering (OSINT).
- Publicly accessible information.
Memory trick: WHOIS: 'Who Owns It, Stupid?'