nerdexam
EC-Council

312-50V13 · Question #468

Lewis, a professional hacker, targeted the loT cameras and devices used by a target venture- capital firm. He used an information-gathering tool to collect information about the loT devices…

The correct answer is A. Censys. Censys is correct because it is a powerful internet-wide scanning and reconnaissance tool specifically designed to discover and monitor IoT devices, open ports, services, and attack surfaces across the entire internet. It collects data from continuous scans and generates…

Submitted by chen.hong· Mar 6, 2026Footprinting and Reconnaissance

Question

Lewis, a professional hacker, targeted the loT cameras and devices used by a target venture- capital firm. He used an information-gathering tool to collect information about the loT devices connected to a network, open ports and services, and the attack surface area. Using this tool, he also generated statistical reports on broad usage patterns and trends. This tool helped Lewis continually monitor every reachable server and device on the Internet, further allowing him to exploit these devices in the network. Which of the following tools was employed by Lewis in the above scenario?

Options

  • ACensys
  • BWapiti
  • CNeuVector
  • DLacework

How the community answered

(58 responses)
  • A
    91% (53)
  • B
    5% (3)
  • C
    2% (1)
  • D
    2% (1)

Explanation

Censys is correct because it is a powerful internet-wide scanning and reconnaissance tool specifically designed to discover and monitor IoT devices, open ports, services, and attack surfaces across the entire internet. It collects data from continuous scans and generates statistical reports on usage patterns and trends, making it a preferred tool for both security researchers and threat actors targeting internet-connected devices.

Why the distractors are wrong:

  • Wapiti (B) is a web application vulnerability scanner focused on testing website security (e.g., SQL injection, XSS), not IoT device discovery or internet-wide scanning.
  • NeuVector (C) is a container security platform designed to protect Kubernetes and Docker environments - it has no IoT reconnaissance functionality.
  • Lacework (D) is a cloud security and compliance monitoring platform, focused on cloud infrastructure anomaly detection rather than IoT device enumeration.

Memory Tip: Think of Censys as a "census" of the internet - just like a population census counts and profiles every person in a country, Censys scans and profiles every reachable device on the internet, making it the go-to tool for internet-wide IoT reconnaissance.

Topics

#Censys#Information Gathering#Reconnaissance#IoT Hacking

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice