EC-Council Certified Ethical Hacker (CEH) v12Information Security and Ethical Hacking OverviewEasy
An ethical hacker is performing a reconnaissance phase against a target organization. They decide to use public search engines, social media, and publicly available financial reports to gather information about the company's structure, employees, and technologies. What ethical hacking methodology step are they currently performing?
- AMaintaining Access
- BScanning
- CGaining Access
- DReconnaissance
Show answer & explanationAnswer & explanation
Correct answer: D. Reconnaissance
Reconnaissance is the initial phase of ethical hacking where the attacker gathers as much information as possible about the target using passive or active methods. Using public search engines, social media, and financial reports are classic examples of passive reconnaissance.
Why the other options are wrong
- A. Maintaining Access involves establishing persistent access to the compromised system.
- B. Scanning involves more active interaction with the target systems to identify open ports, services, and vulnerabilities.
- C. Gaining Access is the phase where the attacker exploits vulnerabilities to gain entry into the system.
Reconnaissance (Hacking)
The initial phase of an ethical hacking engagement, focused on gathering as much information as possible about the target system, network, or organization, often without direct interaction.
- First stage of a penetration test.
- Can be passive (OSINT) or active (port scanning).
- Aims to understand the target's attack surface.
- Provides data for subsequent attack phases.
Memory trick: RGS M C: Recon, Scan, Gain, Maintain, Clear.