CompTIA Security+ (SY0-701)Security Program Management and OversightMedium
A penetration tester begins an engagement by searching public DNS records, WHOIS databases, and employee social media profiles without sending any packets to the target's network. Which activity is the tester performing?
- AActive reconnaissance
- BVulnerability scanning
- CPassive reconnaissance
- DExploitation
Show answer & explanationAnswer & explanation
Correct answer: C. Passive reconnaissance
Passive reconnaissance gathers information about a target using publicly available sources without directly interacting with or touching the target's systems.
Why the other options are wrong
- A. Active reconnaissance involves direct interaction with the target, such as port scanning.
- B. Vulnerability scanning actively probes systems for known weaknesses.
- D. Exploitation involves actively attempting to leverage vulnerabilities to gain access.
Passive Reconnaissance
Information gathering about a target using publicly available sources without directly interacting with the target's systems.
- Includes OSINT sources like WHOIS, DNS, and social media
- Does not generate traffic or logs on the target's systems
- Contrasts with active reconnaissance, which involves direct probing
Memory trick: Passive = peeking from a distance; Active = knocking on the door.