nerdexam
CompTIA

SY0-501 · Question #232

An in-house penetration tester is using a packet capture device to listen in on network communications. This is an example of:

The correct answer is A. Passive reconnaissance. Listening to network communications with a packet capture device without active interaction is a form of information gathering that falls under passive reconnaissance.

Submitted by yousef_jo· Mar 4, 2026Threats, vulnerabilities, and mitigations

Question

An in-house penetration tester is using a packet capture device to listen in on network communications. This is an example of:

Options

  • APassive reconnaissance
  • BPersistence
  • CEscalation of privileges
  • DExploiting the switch

How the community answered

(27 responses)
  • A
    81% (22)
  • B
    4% (1)
  • C
    4% (1)
  • D
    11% (3)

Why each option

Listening to network communications with a packet capture device without active interaction is a form of information gathering that falls under passive reconnaissance.

APassive reconnaissanceCorrect

Passive reconnaissance involves gathering information about a target without directly interacting with it in a way that would be easily detectable. Using a packet capture device to merely listen in on network communications exemplifies this, as it passively collects data without sending probes or actively engaging with systems.

BPersistence

Persistence refers to maintaining access to a compromised system or network over time, which is not the action described by simply listening to traffic.

CEscalation of privileges

Escalation of privileges involves gaining higher-level access or permissions within a system, which is distinct from the initial information gathering phase of packet capture.

DExploiting the switch

While a switch might be exploited to facilitate packet capture in some scenarios, simply using a packet capture device to listen in does not inherently imply an exploit against the switch itself.

Concept tested: Passive reconnaissance in penetration testing

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-115.pdf

Topics

#passive reconnaissance#packet capture#network sniffing#penetration testing

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice