312-50V13 · Question #15
Hackers often raise the trust level of a phishing message by modeling the email to look similar to the internal email used by the target company. This includes using logos, formatting, and names of…
The correct answer is C. Reconnaissance. The process of gathering information about a target, such as company details, employee names, and organizational structure, before launching an attack like phishing is known as reconnaissance.
Question
Options
- AExploration
- BInvestigation
- CReconnaissance
- DEnumeration
How the community answered
(51 responses)- A4% (2)
- B2% (1)
- C94% (48)
Why each option
The process of gathering information about a target, such as company details, employee names, and organizational structure, before launching an attack like phishing is known as reconnaissance.
Exploration is a general term and not a specific, recognized phase in the attack kill chain or information gathering process.
Investigation is a broader term often used in incident response or forensics after an event, not specifically for pre-attack information gathering by an attacker.
Reconnaissance is the initial phase of an attack where an attacker passively gathers as much information as possible about a target. This includes collecting details about company structure, employee names, logos, and email formats to craft believable and trustworthy phishing messages for social engineering.
Enumeration is a more active form of information gathering that typically involves direct interaction with the target system to extract specific details like usernames or service versions, which is distinct from passive research for social engineering.
Concept tested: Reconnaissance phase of cyber attack
Source: https://owasp.org/www-project-web-security-testing-guide/v41/4-Information_Gathering/
Topics
Community Discussion
No community discussion yet for this question.