nerdexam
CompTIA

PT0-001 · Question #92

A penetration tester is required to perform OSINT on staff at a target company after completing the infrastructure aspect. Which of the following would be the BEST step for the penetration tester to…

The correct answer is C. Send spoofed emails to staff to see if staff will respond with sensitive information. In this scenario, since you are trying to preform OSINT on the staff of the company, it would be best to send spoofed emails to the staff to see whether they will respond with sensitive information. Penetration testers need to be ready to incorporate social engineering in their…

Reconnaissance and enumeration

Question

A penetration tester is required to perform OSINT on staff at a target company after completing the infrastructure aspect. Which of the following would be the BEST step for the penetration tester to take?

Options

  • AObtain staff information by calling the company and using social engineering techniques.
  • BVisit the client and use impersonation to obtain information from staff.
  • CSend spoofed emails to staff to see if staff will respond with sensitive information.
  • DSearch the Internet for information on staff such as social networking sites.

How the community answered

(19 responses)
  • A
    5% (1)
  • C
    89% (17)
  • D
    5% (1)

Explanation

In this scenario, since you are trying to preform OSINT on the staff of the company, it would be best to send spoofed emails to the staff to see whether they will respond with sensitive information. Penetration testers need to be ready to incorporate social engineering in their test plan if allowed by the rules of engagement and included in the scope of work.

Topics

#OSINT#staff enumeration#social engineering#information gathering

Community Discussion

No community discussion yet for this question.

Full PT0-001 Practice