CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester is analyzing network traffic captured during a reconnaissance phase. They observe several HTTP requests containing a 'User-Agent' header that reveals the operating system and browser version of the client making the request. This is an example of which type of fingerprinting?

  1. APassive OS Fingerprinting
  2. BActive Service Fingerprinting
  3. CActive OS Fingerprinting
  4. DPassive Network Fingerprinting
Show answer & explanation

Correct answer: A. Passive OS Fingerprinting

Passive OS fingerprinting involves analyzing network traffic (like User-Agent headers, TTL values, TCP window sizes) without sending any probes, to infer the operating system of a host.

Why the other options are wrong

  • B. Active service fingerprinting involves sending specific probes to a port to identify the service and its version, not the OS from a User-Agent.
  • C. Active OS fingerprinting involves sending specially crafted packets to a target to elicit responses that reveal its OS, which is not what's happening here.
  • D. Passive network fingerprinting is too broad; 'Passive OS Fingerprinting' is more specific to identifying the operating system.

Passive OS Fingerprinting

The process of identifying a target's operating system by analyzing existing network traffic, such as HTTP User-Agent strings, TCP window sizes, TTL values, and other network stack characteristics, without directly interacting with the target.

  • Relies on analyzing existing traffic.
  • Does not send probes to the target.
  • User-Agent strings are a key indicator.
  • Considered a reconnaissance technique.

Memory trick: Passive means you observe, Active means you probe.

More Reconnaissance and Enumeration questions