CAS-003 · Question #309
A consultant is hired to perform a passive vulnerability assessment of a company to determine what information might be collected about the company and its employees. The assessment will be…
The correct answer is A. Whois. Whois is a passive reconnaissance technique that queries public domain registration databases. Domain records often include the names, email addresses, phone numbers, and organization details of technical and administrative contacts-roles frequently held by IT administrators…
Question
A consultant is hired to perform a passive vulnerability assessment of a company to determine what information might be collected about the company and its employees. The assessment will be considered successful if the consultant can discover the name of one of the IT administrators. Which of the following is MOST likely to produce the needed information?
Options
- AWhois
- BDNS enumeration
- CVulnerability scanner
- DFingerprinting
How the community answered
(23 responses)- A96% (22)
- C4% (1)
Explanation
Whois is a passive reconnaissance technique that queries public domain registration databases. Domain records often include the names, email addresses, phone numbers, and organization details of technical and administrative contacts-roles frequently held by IT administrators. This requires no interaction with the target's systems and leaves no footprint, satisfying the 'passive' requirement. DNS enumeration (B) reveals hostnames and IP addresses but not personnel names. A vulnerability scanner (C) is active, not passive. Fingerprinting (D) identifies OS and service versions on live systems, also an active technique. Whois is the most direct passive method to discover named individuals associated with a company's IT infrastructure.
Topics
Community Discussion
No community discussion yet for this question.