nerdexam
EC-Council

312-50V11 · Question #42

Which of the following provides a security professional with most information about the system's security posture?

The correct answer is D. Port scanning, banner grabbing, service identification. Port scanning, banner grabbing, and service identification provide direct technical evidence of open ports, running software, and version details - giving the most comprehensive and actionable view of a system's security posture.

Footprinting and Reconnaissance

Question

Which of the following provides a security professional with most information about the system's security posture?

Options

  • AWardriving, warchalking, social engineering
  • BSocial engineering, company site browsing, tailgating
  • CPhishing, spamming, sending trojans
  • DPort scanning, banner grabbing, service identification

How the community answered

(15 responses)
  • B
    7% (1)
  • D
    93% (14)

Why each option

Port scanning, banner grabbing, and service identification provide direct technical evidence of open ports, running software, and version details - giving the most comprehensive and actionable view of a system's security posture.

AWardriving, warchalking, social engineering

Wardriving, warchalking, and social engineering focus on wireless network discovery and human manipulation, providing limited insight into the specific technical security state of a target system.

BSocial engineering, company site browsing, tailgating

Social engineering, company site browsing, and tailgating are passive or physical reconnaissance methods that reveal organizational information but do not assess the technical configuration or vulnerability exposure of systems.

CPhishing, spamming, sending trojans

Phishing, spamming, and deploying trojans are active offensive attack techniques aimed at compromising systems, not assessment methods used to evaluate an existing security posture.

DPort scanning, banner grabbing, service identificationCorrect

Port scanning maps which ports are open and exposed, banner grabbing retrieves service banners that reveal specific software versions potentially affected by known CVEs, and service identification confirms exactly what is running and how it is configured. Together these three techniques produce concrete, technical data about the system's attack surface that can be directly matched against vulnerability databases. This combination is the foundation of any structured vulnerability assessment or penetration test.

Concept tested: Active technical reconnaissance for security posture assessment

Source: https://csrc.nist.gov/publications/detail/sp/800-115/final

Topics

#security posture#reconnaissance techniques#port scanning#banner grabbing

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice