PT0-001 · Question #92
A penetration tester is required to perform OSINT on staff at a target company after completing the infrastructure aspect. Which of the following would be the BEST step for the penetration tester to…
The correct answer is C. Send spoofed emails to staff to see if staff will respond with sensitive information. In this scenario, since you are trying to preform OSINT on the staff of the company, it would be best to send spoofed emails to the staff to see whether they will respond with sensitive information. Penetration testers need to be ready to incorporate social engineering in their…
Question
A penetration tester is required to perform OSINT on staff at a target company after completing the infrastructure aspect. Which of the following would be the BEST step for the penetration tester to take?
Options
- AObtain staff information by calling the company and using social engineering techniques.
- BVisit the client and use impersonation to obtain information from staff.
- CSend spoofed emails to staff to see if staff will respond with sensitive information.
- DSearch the Internet for information on staff such as social networking sites.
How the community answered
(19 responses)- A5% (1)
- C89% (17)
- D5% (1)
Explanation
In this scenario, since you are trying to preform OSINT on the staff of the company, it would be best to send spoofed emails to the staff to see whether they will respond with sensitive information. Penetration testers need to be ready to incorporate social engineering in their test plan if allowed by the rules of engagement and included in the scope of work.
Topics
Community Discussion
No community discussion yet for this question.