nerdexam
GIAC

GSLC · Question #546

You see the career section of a company's Web site and analyze the job profile requirements. You conclude that the company wants professionals who have a sharp knowledge of Windows server 2003 and Win

The correct answer is D. Reconnaissance. Gathering intelligence from publicly available sources such as job postings to learn about a target organization's technology stack is a passive information-gathering technique classified as reconnaissance.

Security Architecture & Engineering

Question

You see the career section of a company's Web site and analyze the job profile requirements. You conclude that the company wants professionals who have a sharp knowledge of Windows server 2003 and Windows active directory installation and placement. Which of the following steps are you using to perform hacking?

Options

  • ACovering tracks
  • BScanning
  • CGaining access
  • DReconnaissance

How the community answered

(39 responses)
  • A
    3% (1)
  • C
    3% (1)
  • D
    95% (37)

Why each option

Gathering intelligence from publicly available sources such as job postings to learn about a target organization's technology stack is a passive information-gathering technique classified as reconnaissance.

ACovering tracks

Covering tracks is the final phase of an attack, involving the deletion of logs and removal of evidence after a system has already been compromised, which has no relation to passively reading a website.

BScanning

Scanning involves actively probing a target's network with tools to discover open ports, running services, and OS versions, which requires direct interaction with the target's infrastructure.

CGaining access

Gaining access involves exploiting discovered vulnerabilities to compromise a system and occurs after reconnaissance and scanning have already been completed.

DReconnaissanceCorrect

Reconnaissance is the first phase of the ethical hacking lifecycle in which an attacker collects publicly available information about a target without directly interacting with its systems - reading a company's job listings to infer its server technologies (Windows Server 2003, Active Directory) is a textbook example of passive reconnaissance that requires no system access or active probing.

Concept tested: Passive reconnaissance in the ethical hacking lifecycle

Source: https://csrc.nist.gov/publications/detail/sp/800-115/final

Topics

#reconnaissance#footprinting#attack methodology#ethical hacking

Community Discussion

No community discussion yet for this question.

Full GSLC Practice