nerdexam
CompTIA

PT0-002 · Question #295

A penetration tester is conducting an engagement against an internet-facing web application and planning a phishing campaign. Which of the following is the BEST passive method of obtaining the…

The correct answer is A. WHOIS domain lookup. A WHOIS domain lookup is the best passive method for obtaining technical contacts for a website. WHOIS records include registrant name, administrative contact, technical contact, billing contact, email addresses, phone numbers, and registrar details - exactly what a penetration…

Information Gathering and Vulnerability Scanning

Question

A penetration tester is conducting an engagement against an internet-facing web application and planning a phishing campaign. Which of the following is the BEST passive method of obtaining the technical contacts for the website?

Options

  • AWHOIS domain lookup
  • BJob listing and recruitment ads
  • CSSL certificate information
  • DPublic data breach dumps

How the community answered

(27 responses)
  • A
    89% (24)
  • B
    4% (1)
  • C
    7% (2)

Explanation

A WHOIS domain lookup is the best passive method for obtaining technical contacts for a website. WHOIS records include registrant name, administrative contact, technical contact, billing contact, email addresses, phone numbers, and registrar details - exactly what a penetration tester needs to identify targets for a phishing campaign. It requires no direct interaction with the target. SSL certificate information may reveal the organization name but rarely includes technical contact details. Job listings are passive but provide HR/role data, not direct technical contacts. Data breach dumps are passive but unreliable and may be outdated or irrelevant.

Topics

#Passive Reconnaissance#Information Gathering#WHOIS#Contact Discovery

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice