nerdexam
EC-Council

112-52 · Question #138

In which phase of penetration testing is information gathered to identify potential targets and their vulnerabilities?

The correct answer is B. Discovery. Discovery is correct because this phase specifically involves active and passive reconnaissance - scanning networks, enumerating services, and identifying vulnerabilities in potential targets before any exploitation occurs. Planning (A) is wrong because that phase defines…

Information Gathering and Vulnerability Analysis

Question

In which phase of penetration testing is information gathered to identify potential targets and their vulnerabilities?

Options

  • APlanning
  • BDiscovery
  • CAttack
  • DReporting

How the community answered

(44 responses)
  • A
    2% (1)
  • B
    93% (41)
  • D
    5% (2)

Explanation

Discovery is correct because this phase specifically involves active and passive reconnaissance - scanning networks, enumerating services, and identifying vulnerabilities in potential targets before any exploitation occurs.

Planning (A) is wrong because that phase defines scope, rules of engagement, and legal agreements - it's about organizing the engagement, not gathering technical intelligence. Attack (C) is wrong because by that phase, target information is already known; the focus shifts to exploiting identified vulnerabilities. Reporting (D) is wrong because it's the final phase where findings are documented and communicated to stakeholders.

Memory tip: Think of Discovery as "detective work" - you're discovering what's there before you act on it. The phases flow logically: Plan the job → Discover the targets → Attack the vulnerabilities → Report the results.

Topics

#Penetration Testing Phases#Information Gathering#Discovery Phase#Vulnerability Identification

Community Discussion

No community discussion yet for this question.

Full 112-52 Practice