nerdexam
EC-Council

312-50V9 · Question #432

A penetration tester was hired to perform a penetration test for a bank. The tester began searching for IP ranges owned by the bank, performing lookups on the bank's DNS servers, reading news…

The correct answer is D. Passive information gathering. The tester is in the passive information gathering phase, collecting data about the target without directly interacting with or probing the bank's systems.

Footprinting and Reconnaissance

Question

A penetration tester was hired to perform a penetration test for a bank. The tester began searching for IP ranges owned by the bank, performing lookups on the bank's DNS servers, reading news articles online about the bank, watching what times the bank employees come into work and leave from work, searching the bank's job postings (paying special attention to IT related jobs), and visiting the local dumpster for the bank's corporate office. What phase of the penetration test is the tester currently in?

Options

  • AInformation reporting
  • BVulnerability assessment
  • CActive information gathering
  • DPassive information gathering

How the community answered

(29 responses)
  • B
    3% (1)
  • C
    3% (1)
  • D
    93% (27)

Why each option

The tester is in the passive information gathering phase, collecting data about the target without directly interacting with or probing the bank's systems.

AInformation reporting

Information reporting is the final phase of a penetration test where findings are documented and delivered to the client, not an information collection phase.

BVulnerability assessment

Vulnerability assessment involves actively scanning and probing systems for known vulnerabilities, which requires direct technical interaction with target systems.

CActive information gathering

Active information gathering involves directly interacting with target systems (e.g., port scanning, banner grabbing), none of which the tester is performing here.

DPassive information gatheringCorrect

Passive information gathering (also called passive reconnaissance) involves collecting information about a target using publicly available sources and physical observation without directly engaging the target's systems. All activities described - DNS lookups, OSINT research, employee observation, job posting analysis, and dumpster diving - are non-intrusive and leave no footprint on the target's network or systems.

Concept tested: Passive reconnaissance vs. active information gathering phases

Source: https://www.oreilly.com/library/view/penetration-testing/9781457185342/ch04.html

Topics

#passive reconnaissance#OSINT#DNS lookup#dumpster diving

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice