Technical OSINT Fundamentals
Final Quiz
Connecting to LMS...
Progress: in progress
Assessment
1. What is technical OSINT?
A. Analysis of lawfully accessible public technical information about internet-facing infrastructure
B. Unauthorized access to private systems
C. Malware development
D. Credential theft
2. Which item is commonly examined in technical OSINT?
A. Stolen databases
B. Domain names, DNS records, certificates, and public repositories
C. Private passwords
D. Restricted dashboards
3. What is a subdomain?
A. A private token
B. A firewall exploit
C. A domain name beneath a parent domain, such as app.example.com
D. A payroll record
4. What can DNS records help identify?
A. Guaranteed control of every system
B. Exact employee locations
C. Private account passwords
D. Public services, mail systems, verification records, and infrastructure relationships
5. Why should DNS data be interpreted cautiously?
A. Records can be stale, proxied, delegated, cached, or unrelated to current operations
B. DNS always proves control
C. DNS removes uncertainty
D. DNS replaces corroboration
6. Why does IP ownership require caution?
A. Addresses never change
B. Addresses may belong to cloud providers, CDNs, shared hosts, or intermediaries
C. Ownership always proves application control
D. Address data needs no context
7. What is certificate transparency useful for?
A. Stealing private keys
B. Bypassing authentication
C. Discovering public certificate records and related hostnames
D. Replacing validation
8. What can a TLS certificate record usually support?
A. That a system is fully secure
B. Permanent ownership of every related host
C. That no risk exists
D. That a certificate covered a name during a defined period
9. Which source may provide legitimate public technical clues?
A. A publicly accessible code repository
B. A private inbox
C. A stolen credential dump
D. A restricted admin portal
10. How should accidental public exposure of a secret be handled?
A. Use it to verify access
B. Report it responsibly through an approved channel and do not use it
C. Publish it broadly
D. Ignore handling policy
11. What is correlation in technical OSINT?
A. Guessing without evidence
B. Removing source context
C. Connecting sourced indicators such as domains, certificates, addresses, and repositories
D. Bypassing controls
12. Why is false attribution a risk?
A. Attribution is always certain
B. One indicator proves responsibility
C. Shared infrastructure never occurs
D. Indicators can be shared, reused, outdated, reassigned, or controlled by third parties
13. What is a risk signal?
A. A public indicator that may warrant further authorized review, validation, or remediation
B. Definite proof of compromise
C. A payroll code
D. A design style
14. Which behavior is inappropriate without explicit authorization?
A. Preserving public source timestamps
B. Intrusive probing or attempting access to systems
C. Reviewing public DNS records
D. Documenting certificate records
15. Which statement best summarizes technical OSINT?
A. It guarantees attribution
B. It replaces human judgment
C. It uses public technical evidence for defensive understanding while respecting scope, ethics, and uncertainty
D. It requires unauthorized access
Submit Quiz
Previous