SY0-701 · Question #652
Which of the following activities uses OSINT?
The correct answer is A. Social engineering testing. Social engineering testing is the correct answer because it relies on OSINT as a core reconnaissance technique - testers gather publicly available information (LinkedIn profiles, company websites, social media, public records) to craft convincing pretexts before executing…
Question
Which of the following activities uses OSINT?
Options
- ASocial engineering testing
- BData analysis of logs
- CCollecting evidence of malicious activity
- DProducing IOC for malicious artifacts
How the community answered
(62 responses)- A74% (46)
- B13% (8)
- C3% (2)
- D10% (6)
Explanation
Social engineering testing is the correct answer because it relies on OSINT as a core reconnaissance technique - testers gather publicly available information (LinkedIn profiles, company websites, social media, public records) to craft convincing pretexts before executing phishing, vishing, or impersonation attacks. Without OSINT, a social engineer has no ammunition.
Why the distractors are wrong:
- B (Log analysis) - Logs are internal, proprietary data sources, not open/public; analyzing them is a SIEM or forensics task, not OSINT.
- C (Collecting malicious activity evidence) - This describes digital forensics or incident response, which involves acquiring artifacts from internal systems, not publicly available sources.
- D (Producing IOCs) - IOC generation comes from reverse-engineering malware samples or analyzing compromised systems - technical threat intelligence work, not open-source gathering.
Memory tip: Think of the attacker lifecycle - before you can manipulate a person (social engineering), you must research them. That research uses open, public sources = OSINT feeds social engineering. The other options all involve internal or technical data that you already possess, not data you gather from the open web.
Topics
Community Discussion
No community discussion yet for this question.