112-52 · Question #138
In which phase of penetration testing is information gathered to identify potential targets and their vulnerabilities?
The correct answer is B. Discovery. Discovery is correct because this phase specifically involves active and passive reconnaissance - scanning networks, enumerating services, and identifying vulnerabilities in potential targets before any exploitation occurs. Planning (A) is wrong because that phase defines…
Question
In which phase of penetration testing is information gathered to identify potential targets and their vulnerabilities?
Options
- APlanning
- BDiscovery
- CAttack
- DReporting
How the community answered
(44 responses)- A2% (1)
- B93% (41)
- D5% (2)
Explanation
Discovery is correct because this phase specifically involves active and passive reconnaissance - scanning networks, enumerating services, and identifying vulnerabilities in potential targets before any exploitation occurs.
Planning (A) is wrong because that phase defines scope, rules of engagement, and legal agreements - it's about organizing the engagement, not gathering technical intelligence. Attack (C) is wrong because by that phase, target information is already known; the focus shifts to exploiting identified vulnerabilities. Reporting (D) is wrong because it's the final phase where findings are documented and communicated to stakeholders.
Memory tip: Think of Discovery as "detective work" - you're discovering what's there before you act on it. The phases flow logically: Plan the job → Discover the targets → Attack the vulnerabilities → Report the results.
Topics
Community Discussion
No community discussion yet for this question.