A penetration tester has been assigned to perform an external penetration assessment of a company. Which of the following steps would BEST help with the passive-information-gathering process? (Choose two.)
A.
Wait outside of the company's building and attempt to tailgate behind an employee.
B.
Perform a vulnerability scan against the company's external netblock, identify exploitable vulnerabilities, and attempt to gain access.
C.
Use domain and IP registry websites to identify the company's external netblocks and external facing applications.
D.
Search social media for information technology employees who post information about the technologies they work with.
E.
Identify the company's external facing webmail application, enumerate user accounts and attempt password guessing to gain access.
Agree! C and D.
Info taken from the PenTest+ Practice Tests Book - SYBEX: "Open-source intelligence (OSINT) is any information that is publicly available and can be passively gathered. Because it is passively gathered, you can’t use methods that actively engage the target organization to gather OSINT. For example, running a vulnerability scan is an active method, as is penetrating the organization’s facility or wheedling information out of a disgruntled employee. On the other hand, gathering information from the organization’s DNS registrar or reading job postings on the organization’s website are examples of passively gathering public information."
This section is not available anymore. Please use the main Exam Page.PT0-001 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
[Removed]
Highly Voted 5Â years, 1Â month agomr_robot
5Â years agodeathfrom
5Â years agosomeguy1393
Highly Voted 4Â years, 4Â months agokloug
Most Recent 2Â years, 2Â months agomiabe
2Â years, 9Â months agoAriel235788
3Â years, 6Â months agocvMikazuki
3Â years, 6Â months agorajeshtwayana
3Â years, 6Â months agoGreyHunter
4Â years, 6Â months ago