nerdexam
EC-Council

312-49 · Question #448

You are a security analyst performing reconnaissance on a company you will be carrying out a penetration test for. You conduct a search for IT jobs on Dice.com and find the following information for…

The correct answer is D. Information vulnerability. The job posting constitutes an information vulnerability because it publicly discloses specific details about the company's internal technology stack - exact product names and versions (Cisco Pix Firewall, Linksys 1376 router, Oracle 11i, MYOB v3.4, Exchange 2003). An attacker…

Submitted by yaw92· Apr 18, 2026Computer Forensics in Today's World

Question

You are a security analyst performing reconnaissance on a company you will be carrying out a penetration test for. You conduct a search for IT jobs on Dice.com and find the following information for an open position: 7+ years experience in Windows Server environment 5+ years experience in Exchange 2000/2003 environment Experience with Cisco Pix Firewall, Linksys 1376 router, Oracle 11i and MYOB v3.4 Accounting software are reQuired MCSA desired, MCSE, CEH preferred No Unix/Linux Experience needed What is this information posted on the job website considered?

Options

  • ATrade secret
  • BSocial engineering exploit
  • CCompetitive exploit
  • DInformation vulnerability

How the community answered

(52 responses)
  • A
    13% (7)
  • B
    10% (5)
  • C
    4% (2)
  • D
    73% (38)

Explanation

The job posting constitutes an information vulnerability because it publicly discloses specific details about the company's internal technology stack - exact product names and versions (Cisco Pix Firewall, Linksys 1376 router, Oracle 11i, MYOB v3.4, Exchange 2003). An attacker can use this information to research known CVEs and exploits for those exact products and versions. This is a common reconnaissance technique called passive information gathering (OSINT), where no direct contact with the target is required. The company inadvertently created an attack roadmap. It is not a trade secret (that requires protection), nor is it inherently a social engineering exploit or a competitive exploit in this context.

Topics

#Reconnaissance#OSINT#Information Vulnerability#Penetration Testing

Community Discussion

No community discussion yet for this question.

Full 312-49 Practice