nerdexam
EC-Council

312-50V13 · Question #15

Hackers often raise the trust level of a phishing message by modeling the email to look similar to the internal email used by the target company. This includes using logos, formatting, and names of…

The correct answer is C. Reconnaissance. The process of gathering information about a target, such as company details, employee names, and organizational structure, before launching an attack like phishing is known as reconnaissance.

Submitted by rania.sa· Mar 6, 2026Reconnaissance Techniques

Question

Hackers often raise the trust level of a phishing message by modeling the email to look similar to the internal email used by the target company. This includes using logos, formatting, and names of the target company. The phishing message will often use the name of the company CEO, President, or Managers. The time a hacker spends performing research to locate this information about a company is known as?

Options

  • AExploration
  • BInvestigation
  • CReconnaissance
  • DEnumeration

How the community answered

(51 responses)
  • A
    4% (2)
  • B
    2% (1)
  • C
    94% (48)

Why each option

The process of gathering information about a target, such as company details, employee names, and organizational structure, before launching an attack like phishing is known as reconnaissance.

AExploration

Exploration is a general term and not a specific, recognized phase in the attack kill chain or information gathering process.

BInvestigation

Investigation is a broader term often used in incident response or forensics after an event, not specifically for pre-attack information gathering by an attacker.

CReconnaissanceCorrect

Reconnaissance is the initial phase of an attack where an attacker passively gathers as much information as possible about a target. This includes collecting details about company structure, employee names, logos, and email formats to craft believable and trustworthy phishing messages for social engineering.

DEnumeration

Enumeration is a more active form of information gathering that typically involves direct interaction with the target system to extract specific details like usernames or service versions, which is distinct from passive research for social engineering.

Concept tested: Reconnaissance phase of cyber attack

Source: https://owasp.org/www-project-web-security-testing-guide/v41/4-Information_Gathering/

Topics

#reconnaissance#phishing#social engineering#information gathering

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice