CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester is performing reconnaissance against a dark-web forum known to be frequented by threat actors. They need to collect information about the forum's structure, user base, and common topics without directly exposing their IP address or leaving any identifiable traces. Which of the following best describes this approach?

  1. AActive reconnaissance using Nmap.
  2. BInternal reconnaissance using local network scans.
  3. CActive reconnaissance using Metasploit.
  4. DPassive reconnaissance using OSINT tools.
Show answer & explanation

Correct answer: D. Passive reconnaissance using OSINT tools.

Passive reconnaissance involves gathering information without direct interaction with the target, thus minimizing the risk of detection. Using OSINT tools to analyze publicly available information (even on the dark web, accessed through anonymity networks) fits this description, as it avoids direct probing. The dark web context emphasizes the need for stealth.

Why the other options are wrong

  • A. Active reconnaissance, especially with Nmap, involves direct interaction and would likely expose the tester's presence.
  • B. Internal reconnaissance implies the tester is already inside the network, which contradicts the scenario of recon against an external dark-web forum.
  • C. Metasploit is an active exploitation framework, which is far from a passive reconnaissance approach.

Passive Reconnaissance

Information gathering without direct interaction with the target system or network, relying on publicly available data or third-party sources.

  • Low risk of detection.
  • Examples: OSINT, public records, social media analysis.
  • Provides a foundational understanding before active engagement.

Memory trick: Recon: Passive hides, Active seeks.

More Reconnaissance and Enumeration questions