exam questions

Exam PT0-001 All Questions

View all questions & answers for the PT0-001 exam

Exam PT0-001 topic 1 question 78 discussion

Actual exam question from CompTIA's PT0-001
Question #: 78
Topic #: 1
[All PT0-001 Questions]

A penetration tester has been assigned to perform an external penetration assessment of a company. Which of the following steps would BEST help with the passive-information-gathering process? (Choose two.)

  • A. Wait outside of the company's building and attempt to tailgate behind an employee.
  • B. Perform a vulnerability scan against the company's external netblock, identify exploitable vulnerabilities, and attempt to gain access.
  • C. Use domain and IP registry websites to identify the company's external netblocks and external facing applications.
  • D. Search social media for information technology employees who post information about the technologies they work with.
  • E. Identify the company's external facing webmail application, enumerate user accounts and attempt password guessing to gain access.
Show Suggested Answer Hide Answer
Suggested Answer: DE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
[Removed]
Highly Voted 5 years, 1 month ago
Passive..... C and D
upvoted 21 times
mr_robot
5 years ago
Agree! C and D. Info taken from the PenTest+ Practice Tests Book - SYBEX: "Open-source intelligence (OSINT) is any information that is publicly available and can be passively gathered. Because it is passively gathered, you can’t use methods that actively engage the target organization to gather OSINT. For example, running a vulnerability scan is an active method, as is penetrating the organization’s facility or wheedling information out of a disgruntled employee. On the other hand, gathering information from the organization’s DNS registrar or reading job postings on the organization’s website are examples of passively gathering public information."
upvoted 12 times
deathfrom
5 years ago
Agreed!
upvoted 7 times
...
...
...
someguy1393
Highly Voted 4 years, 4 months ago
Definitely C & D
upvoted 7 times
...
kloug
Most Recent 2 years, 2 months ago
c,d correct
upvoted 1 times
...
miabe
2 years, 9 months ago
Selected Answer: CD
looks good to me
upvoted 1 times
...
Ariel235788
3 years, 6 months ago
E was passive until you begin password guessing, then it became an Active attack. C and D are the only 2 that are passive in the list
upvoted 2 times
...
cvMikazuki
3 years, 6 months ago
C D la wehhh passive BOY. Cohort 1-2021
upvoted 1 times
...
rajeshtwayana
3 years, 6 months ago
c and d is correct
upvoted 1 times
...
GreyHunter
4 years, 6 months ago
C,D are the correct answer.
upvoted 7 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago