nerdexam
GIAC

GPEN · Question #63

Which of the following penetration testing phases involves gathering data from whois, DNS, and network scanning, which helps in mapping a target network and provides valuable information regarding the

The correct answer is C. Pre-attack phase. The pre-attack phase of penetration testing encompasses all reconnaissance activities - passive and active - used to gather target information before any exploitation attempt.

Penetration Testing Foundations & Reconnaissance

Question

Which of the following penetration testing phases involves gathering data from whois, DNS, and network scanning, which helps in mapping a target network and provides valuable information regarding the operating system and applications running on the systems?

Options

  • APost-attack phase
  • BAttack phase
  • CPre-attack phase
  • DOn-attack phase

How the community answered

(34 responses)
  • A
    15% (5)
  • B
    6% (2)
  • C
    74% (25)
  • D
    6% (2)

Why each option

The pre-attack phase of penetration testing encompasses all reconnaissance activities - passive and active - used to gather target information before any exploitation attempt.

APost-attack phase

The post-attack phase occurs after exploitation has concluded and covers activities such as evidence collection, system restoration, and report writing.

BAttack phase

The attack phase is when the tester actively exploits the vulnerabilities discovered during reconnaissance to gain unauthorized access to target systems.

CPre-attack phaseCorrect

In the EC-Council penetration testing methodology, the pre-attack phase is dedicated entirely to information gathering and reconnaissance. Testers use techniques such as whois lookups, DNS enumeration, and network scanning to map IP ranges, identify operating systems, enumerate running services, and profile the target environment. All of this intelligence is collected prior to any active exploitation so the tester can plan an informed attack strategy.

DOn-attack phase

'On-attack phase' is not a recognized stage in standard penetration testing methodologies such as those defined by EC-Council or PTES.

Concept tested: Penetration testing pre-attack reconnaissance phase

Source: http://www.pentest-standard.org/index.php/Intelligence_Gathering

Topics

#pre-attack phase#reconnaissance#WHOIS#DNS enumeration

Community Discussion

No community discussion yet for this question.

Full GPEN Practice