PT0-001 · Question #136
A penetration tester has been assigned to perform an external penetration assessment of a company. Which of the following steps would BEST help with the passive-information-gathering process?…
The correct answer is C. Use domain and IP registry websites to identify the company's external netblocks and external D. Search social media for information technology employees who post information about the. Passive information gathering relies exclusively on publicly available data sources and involves no direct interaction with or packets sent to the target organization.
Question
A penetration tester has been assigned to perform an external penetration assessment of a company. Which of the following steps would BEST help with the passive-information-gathering process? (Choose two.)
Options
- AWait outside of the company's building and attempt to tailgate behind an employee.
- BPerform a vulnerability scan against the company's external netblock, identify exploitable
- CUse domain and IP registry websites to identify the company's external netblocks and external
- DSearch social media for information technology employees who post information about the
- EIdentify the company's external facing webmail application, enumerate user accounts and attempt
How the community answered
(25 responses)- A4% (1)
- C92% (23)
- E4% (1)
Why each option
Passive information gathering relies exclusively on publicly available data sources and involves no direct interaction with or packets sent to the target organization.
Tailgating an employee into a building is an active physical social engineering technique that requires in-person presence and direct interaction, not passive information gathering.
Running a vulnerability scan actively sends probe packets to the target's external netblock, which constitutes active reconnaissance and could alert the organization.
Domain and IP registry services such as WHOIS, ARIN, and RIPE provide publicly available registration records that reveal a company's external netblocks and IP ranges without sending any traffic to target systems, making this a purely passive OSINT technique.
Searching social media for IT employees who publicly share infrastructure details involves no direct interaction with target systems and relies entirely on open-source intelligence, which is the definition of passive reconnaissance.
Enumerating webmail user accounts and attempting access involves directly interacting with the target's systems and constitutes active exploitation activity, not passive gathering.
Concept tested: Passive OSINT techniques for external penetration reconnaissance
Source: https://csrc.nist.gov/publications/detail/sp/800-115/final
Topics
Community Discussion
No community discussion yet for this question.