CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium
A penetration tester is targeting a corporate network and has identified several public-facing IP addresses. They want to gather as much information as possible about the network infrastructure, including routing information and potential administrative contacts, without directly scanning the target. Which OSINT technique would be most effective for this purpose?
- ANmap service detection.
- BWHOIS lookups.
- CDNS zone transfers.
- DSNMP enumeration.
Show answer & explanationAnswer & explanation
Correct answer: B. WHOIS lookups.
WHOIS lookups provide registration details for domain names and IP addresses, often including administrative and technical contact information, as well as nameserver and sometimes routing details, all passively.
Why the other options are wrong
- A. Nmap service detection is an active scanning technique that sends packets to the target, which is not passive.
- C. DNS zone transfers are active enumeration techniques that request a full copy of a domain's DNS records, which can be blocked.
- D. SNMP enumeration is an active technique that queries network devices for configuration and status information, requiring direct interaction with the target.
WHOIS Lookup
A query protocol used to retrieve registration information for domain names and IP address blocks, often revealing contact details, registrars, and nameservers.
- Provides registrant contact information.
- Useful for identifying domain owners and network blocks.
- Considered a passive reconnaissance technique.
Memory trick: Who is behind that domain? WHOIS knows passively.