nerdexam
CompTIA

PT0-002 · Question #192

A security firm has been hired to perform an external penetration test against a company. The only information the firm received was the company name. Which of the following passive reconnaissance…

The correct answer is C. Runtime the company's vendor/supply chain. For an external penetration test with only a company name, researching the company's vendor and supply chain can yield significant initial intelligence by identifying third-party dependencies and potential attack vectors not immediately apparent from the company's own public…

Reconnaissance and enumeration

Question

A security firm has been hired to perform an external penetration test against a company. The only information the firm received was the company name. Which of the following passive reconnaissance approaches would be MOST likely to yield positive initial results?

Options

  • ASpecially craft and deploy phishing emails to key company leaders.
  • BRun a vulnerability scan against the company's external website.
  • CRuntime the company's vendor/supply chain.
  • DScrape web presences and social-networking sites.

How the community answered

(17 responses)
  • A
    6% (1)
  • B
    24% (4)
  • C
    53% (9)
  • D
    18% (3)

Why each option

For an external penetration test with only a company name, researching the company's vendor and supply chain can yield significant initial intelligence by identifying third-party dependencies and potential attack vectors not immediately apparent from the company's own public web presence.

ASpecially craft and deploy phishing emails to key company leaders.

Deploying phishing emails is an active social engineering technique, not passive reconnaissance, and requires prior knowledge of target email addresses.

BRun a vulnerability scan against the company's external website.

Running a vulnerability scan is an active assessment method that directly interacts with the target, thus not a passive reconnaissance approach.

CRuntime the company's vendor/supply chain.Correct

Researching a company's vendor and supply chain (assuming 'Runtime' is a typo for 'Research/Review') is a highly effective passive reconnaissance technique that reveals critical third-party dependencies, technologies, and potential vulnerabilities within the broader attack surface, which can be more impactful than direct web scraping for initial external assessment.

DScrape web presences and social-networking sites.

While scraping web presences and social-networking sites is a valid passive reconnaissance technique, researching the vendor/supply chain can often provide more strategic insights into third-party dependencies and broader attack vectors for an external test, making it a potentially more 'positive' initial result.

Concept tested: Passive reconnaissance techniques, OSINT

Topics

#Passive Reconnaissance#Open Source Intelligence (OSINT)#External Penetration Testing#Supply Chain Analysis

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice