312-49 · Question #448
You are a security analyst performing reconnaissance on a company you will be carrying out a penetration test for. You conduct a search for IT jobs on Dice.com and find the following information for…
The correct answer is D. Information vulnerability. The job posting constitutes an information vulnerability because it publicly discloses specific details about the company's internal technology stack - exact product names and versions (Cisco Pix Firewall, Linksys 1376 router, Oracle 11i, MYOB v3.4, Exchange 2003). An attacker…
Question
You are a security analyst performing reconnaissance on a company you will be carrying out a penetration test for. You conduct a search for IT jobs on Dice.com and find the following information for an open position: 7+ years experience in Windows Server environment 5+ years experience in Exchange 2000/2003 environment Experience with Cisco Pix Firewall, Linksys 1376 router, Oracle 11i and MYOB v3.4 Accounting software are reQuired MCSA desired, MCSE, CEH preferred No Unix/Linux Experience needed What is this information posted on the job website considered?
Options
- ATrade secret
- BSocial engineering exploit
- CCompetitive exploit
- DInformation vulnerability
How the community answered
(52 responses)- A13% (7)
- B10% (5)
- C4% (2)
- D73% (38)
Explanation
The job posting constitutes an information vulnerability because it publicly discloses specific details about the company's internal technology stack - exact product names and versions (Cisco Pix Firewall, Linksys 1376 router, Oracle 11i, MYOB v3.4, Exchange 2003). An attacker can use this information to research known CVEs and exploits for those exact products and versions. This is a common reconnaissance technique called passive information gathering (OSINT), where no direct contact with the target is required. The company inadvertently created an attack roadmap. It is not a trade secret (that requires protection), nor is it inherently a social engineering exploit or a competitive exploit in this context.
Topics
Community Discussion
No community discussion yet for this question.