nerdexam
CompTIA

PT0-001 · Question #230

At the information gathering stage, a penetration tester is trying to passively identify the technology running on a client's website. Which of the following approached should the penetration tester…

The correct answer is A. Run a spider scan in Burp Suite. https://relevant.software/blog/penetration-testing-for-web-applications/

Reconnaissance and enumeration

Question

At the information gathering stage, a penetration tester is trying to passively identify the technology running on a client's website. Which of the following approached should the penetration tester take?

Options

  • ARun a spider scan in Burp Suite.
  • BUse web aggregators such as BuiltWith and Netcraft
  • CRun a web scraper and pull the website's content.
  • DUse Nmap to fingerprint the website's technology.

How the community answered

(62 responses)
  • A
    92% (57)
  • B
    2% (1)
  • C
    5% (3)
  • D
    2% (1)

Explanation

https://relevant.software/blog/penetration-testing-for-web-applications/

Topics

#passive reconnaissance#web fingerprinting#OSINT#information gathering

Community Discussion

No community discussion yet for this question.

Full PT0-001 Practice