nerdexam
CompTIA

PT0-001 · Question #90

A penetration tester is designing a phishing campaign and wants to build list of users (or the target organization. Which of the following techniques would be the MOST appropriate? (Select TWO)

The correct answer is D. Harvest users from social networking sites. E. Socially engineer the corporate call center. Building a user list for phishing requires reconnaissance techniques that surface actual employee identities, making social media harvesting and direct social engineering the most effective and targeted approaches.

Reconnaissance and enumeration

Question

A penetration tester is designing a phishing campaign and wants to build list of users (or the target organization. Which of the following techniques would be the MOST appropriate? (Select TWO)

Options

  • AQuery an Internet WHOIS database.
  • BSearch posted job listings.
  • CScrape the company website.
  • DHarvest users from social networking sites.
  • ESocially engineer the corporate call center.

How the community answered

(55 responses)
  • A
    2% (1)
  • B
    7% (4)
  • C
    2% (1)
  • D
    89% (49)

Why each option

Building a user list for phishing requires reconnaissance techniques that surface actual employee identities, making social media harvesting and direct social engineering the most effective and targeted approaches.

AQuery an Internet WHOIS database.

WHOIS database queries return domain registration and organizational contact data, not a list of individual employee usernames or email accounts.

BSearch posted job listings.

Job listings reveal roles and technologies in use but typically do not enumerate specific current employees needed for a targeted phishing user list.

CScrape the company website.

Scraping the company website may surface a few staff names from pages such as 'About Us,' but it is far less comprehensive than social networks or direct social engineering for building a full user list.

DHarvest users from social networking sites.Correct

Social networking sites such as LinkedIn expose employee names, email formats, roles, and organizational structure, making them ideal passive OSINT sources for enumerating users at a target organization.

ESocially engineer the corporate call center.Correct

Socially engineering the corporate call center can directly elicit employee names, departments, and contact details from staff who may not verify the caller's identity, yielding verified user information.

Concept tested: OSINT user enumeration techniques for phishing campaigns

Source: https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/01-Information_Gathering/README

Topics

#user enumeration#OSINT#social media harvesting#phishing preparation

Community Discussion

No community discussion yet for this question.

Full PT0-001 Practice