nerdexam
EC-Council

312-50V9 · Question #351

A company recently hired your team of Ethical Hackers to test the security of their network systems. The company wants to have the attack be as realistic as possible. They did not provide any…

The correct answer is B. Reconnaissance. The correct answer is B. Reconnaissance. In ethical hacking, the phases typically follow: Reconnaissance → Scanning → Enumeration → Exploitation → Escalation. Since the team was given only the company name and no technical details (IP ranges, systems, credentials), they must…

Footprinting and Reconnaissance

Question

A company recently hired your team of Ethical Hackers to test the security of their network systems. The company wants to have the attack be as realistic as possible. They did not provide any information besides the name of their company. What phase of security testing would your team jump in right away?

Options

  • AScanning
  • BReconnaissance
  • CEscalation
  • DEnumeration

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    88% (22)
  • C
    4% (1)
  • D
    4% (1)

Explanation

The correct answer is B. Reconnaissance. In ethical hacking, the phases typically follow: Reconnaissance → Scanning → Enumeration → Exploitation → Escalation. Since the team was given only the company name and no technical details (IP ranges, systems, credentials), they must start with Reconnaissance - the information-gathering phase. This involves passively and/or actively collecting data about the target (domain names, public records, WHOIS, DNS, employee info, etc.) before any technical scanning begins. Scanning (A) and Enumeration (D) come later once targets are identified, and Escalation (C) is a post-exploitation phase.

Topics

#black box testing#reconnaissance#penetration testing phases#information gathering

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice