nerdexam
CompTIA

CAS-001 · Question #124

The security manager of a company has hired an external consultant to conduct a security assessment of the company network. The contract stipulates that the consultant is not allowed to transmit any…

The correct answer is B. Protocol analyzer. A protocol analyzer (packet sniffer/network analyzer, e.g., Wireshark) operates in passive/promiscuous mode - it captures and analyzes traffic already flowing on the network without injecting or transmitting any packets of its own. From captured traffic, an analyst can read MAC…

Research and Analysis

Question

The security manager of a company has hired an external consultant to conduct a security assessment of the company network. The contract stipulates that the consultant is not allowed to transmit any data on the company network while performing wired and wireless security assessments. Which of the following technical means can the consultant use to determine the manufacturer and likely operating system of the company wireless and wired network devices, as well as the computers connected to the company network?

Options

  • ASocial engineering
  • BProtocol analyzer
  • CPort scanner
  • DGrey box testing

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    86% (31)
  • C
    3% (1)
  • D
    8% (3)

Explanation

A protocol analyzer (packet sniffer/network analyzer, e.g., Wireshark) operates in passive/promiscuous mode - it captures and analyzes traffic already flowing on the network without injecting or transmitting any packets of its own. From captured traffic, an analyst can read MAC address OUI prefixes to identify hardware manufacturers, fingerprint operating systems through TCP/IP stack behavior (TTL values, window sizes, TCP options), and identify device types from protocols in use. This satisfies the contract requirement of zero data transmission. A port scanner (C) actively sends probe packets, violating the contract. Social engineering (A) is non-technical. Grey box testing (D) describes a testing methodology (partial knowledge), not a specific passive technical tool. Only a protocol analyzer can gather the required information entirely passively.

Topics

#passive reconnaissance#protocol analyzer#network assessment#wireless security

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice