nerdexam
IISFA

II0-001 · Question #221

Footprinting is the process of accumulating data on a ... .. host system.

The correct answer is A. Attack Source. There's an error in the answer key you've been given - option A (Attack Source) is actually incorrect. Footprinting is a reconnaissance technique used to collect information about an attack target - the host or network a threat actor intends to compromise. That makes B (Attack…

Question

Footprinting is the process of accumulating data on a ... .. host system.

Options

  • AAttack Source
  • BAttack target
  • CAttack intermediary
  • DDark Network

How the community answered

(49 responses)
  • A
    73% (36)
  • B
    8% (4)
  • C
    14% (7)
  • D
    4% (2)

Explanation

There's an error in the answer key you've been given - option A (Attack Source) is actually incorrect.

Footprinting is a reconnaissance technique used to collect information about an attack target - the host or network a threat actor intends to compromise. That makes B (Attack Target) the correct answer. Footprinting gathers details like IP ranges, open ports, OS versions, and employee names about the victim, not the attacker's own infrastructure.

Why the distractors are wrong:

  • A (Attack Source) - incorrect; an attacker already knows their own system. Footprinting looks outward at the target, not inward.
  • C (Attack Intermediary) - intermediaries (e.g., proxies, stepping-stone hosts) are used to route attacks, not what footprinting is defined around.
  • D (Dark Network) - a dark network refers to unmonitored or unrouted IP space; it has no standard role in the footprinting definition.

Memory tip: Think of a burglar "casing" a building before robbing it - they study the target (the building), not themselves. Footprinting = casing the target.

Recommendation: Flag this to your instructor or the exam source. The answer key appears to have a typo - B is the correct answer per standard CEH/CompTIA Security+ definitions of footprinting.

Community Discussion

No community discussion yet for this question.

Full II0-001 Practice