SY0-501 · Question #557
While performing a penetration test, the technicians want their efforts to go unnoticed for as long as possible while they gather useful data about the network they are assessing. Which of the…
The correct answer is C. Packet sniffer. The scenario requires a stealthy method for gathering network data during a penetration test, emphasizing remaining unnoticed. A packet sniffer is the most effective tool for passive, undetectable information collection.
Question
While performing a penetration test, the technicians want their efforts to go unnoticed for as long as possible while they gather useful data about the network they are assessing. Which of the following would be the BEST choice for the technicians?
Options
- AVulnerability scanner
- BOffline password cracker
- CPacket sniffer
- DBanner grabbing
How the community answered
(58 responses)- A3% (2)
- B7% (4)
- C78% (45)
- D12% (7)
Why each option
The scenario requires a stealthy method for gathering network data during a penetration test, emphasizing remaining unnoticed. A packet sniffer is the most effective tool for passive, undetectable information collection.
A vulnerability scanner actively sends probes and requests to target systems to identify weaknesses, generating significant network traffic and logs that are easily detectable by network security controls.
An offline password cracker processes previously acquired hash files without directly interacting with the target network for initial data gathering, making it irrelevant for the active reconnaissance phase described.
A packet sniffer operates passively by listening to and capturing network traffic without sending any probes or actively interacting with network services. This allows technicians to gather extensive data, such as communication patterns, protocols in use, and potentially sensitive information, all while minimizing their footprint and remaining undetected on the network for an extended period.
Banner grabbing involves actively connecting to network services (e.g., HTTP, FTP, SSH) to retrieve version information, which generates distinct network traffic and can be logged by the target system, thus being detectable.
Concept tested: Passive network reconnaissance techniques
Topics
Community Discussion
No community discussion yet for this question.