312-50V10 · Question #782
Hackers often raise the trust level of a phishing message by modeling the email to look similar to the internal email used by the target company. This includes using logos, formatting, and names of th
The correct answer is C. Reconnaissance. The pre-attack research phase where a hacker gathers information about a target - such as logos, executive names, and internal structure - is called reconnaissance.
Question
Hackers often raise the trust level of a phishing message by modeling the email to look similar to the internal email used by the target company. This includes using logos, formatting, and names of the target company. The phishing message will often use the name of the company CEO, President, or Managers. The time a hacker spends performing research to locate this information about a company is known as?
Options
- AExploration
- BInvestigation
- CReconnaissance
- DEnumeration
How the community answered
(46 responses)- A2% (1)
- B4% (2)
- C93% (43)
Why each option
The pre-attack research phase where a hacker gathers information about a target - such as logos, executive names, and internal structure - is called reconnaissance.
Exploration is not a recognized phase in standard attack methodology or cybersecurity frameworks and is used here as a generic, non-technical distractor.
Investigation is not a defined phase in penetration testing or attack lifecycle frameworks and lacks the specific technical meaning that reconnaissance carries in cybersecurity.
Reconnaissance is the systematic process of gathering intelligence about a target prior to launching an attack, including passive research such as reviewing public websites, social media profiles, and corporate directories. In spear-phishing contexts, this phase allows attackers to craft convincing messages using authentic company branding, executive names, and internal terminology to increase the probability that the target will be deceived.
Enumeration is a specific active technique used after initial network access or scanning to extract detailed system information such as user accounts, services, and shares - it is more targeted and technical than the broad passive research described in the question.
Concept tested: Reconnaissance phase in the cyber attack lifecycle
Source: https://attack.mitre.org/tactics/TA0043/
Topics
Community Discussion
No community discussion yet for this question.