GSEC · Question #248
Which attack stage mirrors the Information Gathering phase used in penetration testing methodology?
The correct answer is A. Reconnaissance. Reconnaissance in the attacker lifecycle directly mirrors the Information Gathering phase in penetration testing, as both focus on passively and actively collecting target intelligence before any exploitation.
Question
Which attack stage mirrors the Information Gathering phase used in penetration testing methodology?
Options
- AReconnaissance
- BClearing tracks
- CScanning
- DGaining access
How the community answered
(37 responses)- A81% (30)
- B5% (2)
- C3% (1)
- D11% (4)
Why each option
Reconnaissance in the attacker lifecycle directly mirrors the Information Gathering phase in penetration testing, as both focus on passively and actively collecting target intelligence before any exploitation.
Reconnaissance is the initial stage of the cyber attack lifecycle where an attacker gathers information about the target using passive techniques such as OSINT, WHOIS lookups, and DNS enumeration, as well as active techniques. This maps directly to the Information Gathering phase in formal penetration testing methodology, which similarly aims to build a complete picture of the target before progressing to active exploitation.
Clearing tracks is the final post-exploitation phase focused on removing evidence of intrusion such as deleting logs, not on collecting information about the target.
Scanning is a subsequent phase that involves active probing of discovered targets with tools like port scanners and vulnerability scanners, occurring after initial information has already been gathered.
Gaining access is the exploitation phase where identified vulnerabilities are actively leveraged to compromise a system, well past the information gathering stage.
Concept tested: Mapping attacker reconnaissance to pentest methodology phases
Source: https://www.eccouncil.org/train-certify/certified-ethical-hacker-ceh/
Topics
Community Discussion
No community discussion yet for this question.