CAS-003 · Question #613
A company contracts a security consultant to perform a remote white-box penetration test. The company wants the consultant to focus on Internet-facing services without negatively impacting…
The correct answer is B. WHOIS registry E. Internal routing tables. NOTE: The listed correct answers are B and E, but E (internal routing tables) requires internal network access and is not accessible during a remote penetration test. The correct pair for remotely identifying an internet-facing attack surface is B (WHOIS registry) and C (DNS…
Question
A company contracts a security consultant to perform a remote white-box penetration test. The company wants the consultant to focus on Internet-facing services without negatively impacting production services. Which of the following is the consultant MOST likely to use to identify the company's attack surface? (Select TWO)
Options
- AWeb crawler
- BWHOIS registry
- CDNS records
- DCompany's firewall ACL
- EInternal routing tables
- FDirectory service queries
How the community answered
(24 responses)- A4% (1)
- B79% (19)
- C4% (1)
- D13% (3)
Explanation
NOTE: The listed correct answers are B and E, but E (internal routing tables) requires internal network access and is not accessible during a remote penetration test. The correct pair for remotely identifying an internet-facing attack surface is B (WHOIS registry) and C (DNS records). WHOIS reveals IP address ranges, domain registrant details, and organizational information. DNS records expose subdomains, mail servers, and other internet-facing services. Both are publicly accessible and are standard reconnaissance tools for external attack surface mapping. Internal routing tables (E) and directory service queries (F) are only accessible once inside the network, which contradicts the remote testing scope.
Topics
Community Discussion
No community discussion yet for this question.