GPEN · Question #63
Which of the following penetration testing phases involves gathering data from whois, DNS, and network scanning, which helps in mapping a target network and provides valuable information regarding the
The correct answer is C. Pre-attack phase. The pre-attack phase of penetration testing encompasses all reconnaissance activities - passive and active - used to gather target information before any exploitation attempt.
Question
Which of the following penetration testing phases involves gathering data from whois, DNS, and network scanning, which helps in mapping a target network and provides valuable information regarding the operating system and applications running on the systems?
Options
- APost-attack phase
- BAttack phase
- CPre-attack phase
- DOn-attack phase
How the community answered
(34 responses)- A15% (5)
- B6% (2)
- C74% (25)
- D6% (2)
Why each option
The pre-attack phase of penetration testing encompasses all reconnaissance activities - passive and active - used to gather target information before any exploitation attempt.
The post-attack phase occurs after exploitation has concluded and covers activities such as evidence collection, system restoration, and report writing.
The attack phase is when the tester actively exploits the vulnerabilities discovered during reconnaissance to gain unauthorized access to target systems.
In the EC-Council penetration testing methodology, the pre-attack phase is dedicated entirely to information gathering and reconnaissance. Testers use techniques such as whois lookups, DNS enumeration, and network scanning to map IP ranges, identify operating systems, enumerate running services, and profile the target environment. All of this intelligence is collected prior to any active exploitation so the tester can plan an informed attack strategy.
'On-attack phase' is not a recognized stage in standard penetration testing methodologies such as those defined by EC-Council or PTES.
Concept tested: Penetration testing pre-attack reconnaissance phase
Source: http://www.pentest-standard.org/index.php/Intelligence_Gathering
Topics
Community Discussion
No community discussion yet for this question.