PT0-001 · Question #90
A penetration tester is designing a phishing campaign and wants to build list of users (or the target organization. Which of the following techniques would be the MOST appropriate? (Select TWO)
The correct answer is D. Harvest users from social networking sites. E. Socially engineer the corporate call center. Building a user list for phishing requires reconnaissance techniques that surface actual employee identities, making social media harvesting and direct social engineering the most effective and targeted approaches.
Question
A penetration tester is designing a phishing campaign and wants to build list of users (or the target organization. Which of the following techniques would be the MOST appropriate? (Select TWO)
Options
- AQuery an Internet WHOIS database.
- BSearch posted job listings.
- CScrape the company website.
- DHarvest users from social networking sites.
- ESocially engineer the corporate call center.
How the community answered
(55 responses)- A2% (1)
- B7% (4)
- C2% (1)
- D89% (49)
Why each option
Building a user list for phishing requires reconnaissance techniques that surface actual employee identities, making social media harvesting and direct social engineering the most effective and targeted approaches.
WHOIS database queries return domain registration and organizational contact data, not a list of individual employee usernames or email accounts.
Job listings reveal roles and technologies in use but typically do not enumerate specific current employees needed for a targeted phishing user list.
Scraping the company website may surface a few staff names from pages such as 'About Us,' but it is far less comprehensive than social networks or direct social engineering for building a full user list.
Social networking sites such as LinkedIn expose employee names, email formats, roles, and organizational structure, making them ideal passive OSINT sources for enumerating users at a target organization.
Socially engineering the corporate call center can directly elicit employee names, departments, and contact details from staff who may not verify the caller's identity, yielding verified user information.
Concept tested: OSINT user enumeration techniques for phishing campaigns
Source: https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/01-Information_Gathering/README
Topics
Community Discussion
No community discussion yet for this question.