nerdexam
CompTIA

CS0-003 · Question #34

An analyst finds that an IP address outside of the company network that is being used to run network and vulnerability scans across external-facing assets. Which of the following steps of an attack…

The correct answer is B. Reconnaissance. Reconnaissance is the first step in most attack frameworks. It is the process of gathering information about a target in order to plan an attack. This information can include things like the target's network topology, IP addresses, and open ports. In this case, the analyst has…

Submitted by rania.sa· Mar 6, 2026Security operations

Question

An analyst finds that an IP address outside of the company network that is being used to run network and vulnerability scans across external-facing assets. Which of the following steps of an attack framework is the analyst witnessing?

Options

  • AExploitation
  • BReconnaissance
  • CCommand and control
  • DActions on objectives

How the community answered

(25 responses)
  • B
    96% (24)
  • C
    4% (1)

Explanation

Reconnaissance is the first step in most attack frameworks. It is the process of gathering information about a target in order to plan an attack. This information can include things like the target's network topology, IP addresses, and open ports. In this case, the analyst has found that an IP address outside of the company network is being used to run network and vulnerability scans across external-facing assets. This is a clear sign that the IP address is being used for reconnaissance.

Topics

#reconnaissance#attack framework#vulnerability scanning#external assets

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice