nerdexam
CompTIA

PT0-003 · Question #225

A company hires a penetration tester to perform an external attack surface review as part of a security engagement. The company informs the tester that the main company domain to investigate is…

The correct answer is A. Perform information-gathering techniques to review internet-facing assets for the company. An external attack surface review focuses on identifying publicly accessible systems, services, and information. The correct first step is to perform reconnaissance and enumeration techniques to discover internet-facing assets (e.g., subdomains, exposed services, certificates…

Submitted by chiamaka_o· Mar 6, 2026Reconnaissance and Enumeration

Question

A company hires a penetration tester to perform an external attack surface review as part of a security engagement. The company informs the tester that the main company domain to investigate is comptia.org. Which of the following should the tester do to accomplish the assessment objective?

Options

  • APerform information-gathering techniques to review internet-facing assets for the company.
  • BPerform a phishing assessment to try to gain access to more resources and users' computers.
  • CPerform a physical security review to identify vulnerabilities that could affect the company.
  • DPerform a vulnerability assessment over the main domain address provided by the client.

How the community answered

(26 responses)
  • A
    92% (24)
  • B
    4% (1)
  • D
    4% (1)

Explanation

An external attack surface review focuses on identifying publicly accessible systems, services, and information. The correct first step is to perform reconnaissance and enumeration techniques to discover internet-facing assets (e.g., subdomains, exposed services, certificates, etc.) associated with comptia.org.

Topics

#reconnaissance#information gathering#external attack surface#OSINT

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice