312-50V9 · Question #432
A penetration tester was hired to perform a penetration test for a bank. The tester began searching for IP ranges owned by the bank, performing lookups on the bank's DNS servers, reading news…
The correct answer is D. Passive information gathering. The tester is in the passive information gathering phase, collecting data about the target without directly interacting with or probing the bank's systems.
Question
A penetration tester was hired to perform a penetration test for a bank. The tester began searching for IP ranges owned by the bank, performing lookups on the bank's DNS servers, reading news articles online about the bank, watching what times the bank employees come into work and leave from work, searching the bank's job postings (paying special attention to IT related jobs), and visiting the local dumpster for the bank's corporate office. What phase of the penetration test is the tester currently in?
Options
- AInformation reporting
- BVulnerability assessment
- CActive information gathering
- DPassive information gathering
How the community answered
(29 responses)- B3% (1)
- C3% (1)
- D93% (27)
Why each option
The tester is in the passive information gathering phase, collecting data about the target without directly interacting with or probing the bank's systems.
Information reporting is the final phase of a penetration test where findings are documented and delivered to the client, not an information collection phase.
Vulnerability assessment involves actively scanning and probing systems for known vulnerabilities, which requires direct technical interaction with target systems.
Active information gathering involves directly interacting with target systems (e.g., port scanning, banner grabbing), none of which the tester is performing here.
Passive information gathering (also called passive reconnaissance) involves collecting information about a target using publicly available sources and physical observation without directly engaging the target's systems. All activities described - DNS lookups, OSINT research, employee observation, job posting analysis, and dumpster diving - are non-intrusive and leave no footprint on the target's network or systems.
Concept tested: Passive reconnaissance vs. active information gathering phases
Source: https://www.oreilly.com/library/view/penetration-testing/9781457185342/ch04.html
Topics
Community Discussion
No community discussion yet for this question.