Penetration Testing Concepts | Enumeration and Target Information Gathering | SY0-601 Exam

Enumeration and Target Information Gathering

Prev Question Next Question

Question

Which of the following penetration testing concepts is being used when an attacker uses public Internet databases to enumerate and learn more about a target?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D. E.

A.

The answer to this question is A. Reconnaissance.

Reconnaissance is the first phase of penetration testing, in which an attacker gathers information about the target system or network in order to find potential vulnerabilities and exploit them. In this phase, an attacker uses publicly available resources, such as Internet databases, social media, or public records, to gather information about the target. The goal of reconnaissance is to learn as much as possible about the target in order to identify potential attack vectors.

Initial exploitation is the second phase of penetration testing, in which an attacker attempts to gain access to the target system or network by exploiting known vulnerabilities. Pivoting is the act of using a compromised system to attack other systems on the same network. Vulnerability scanning is the automated process of scanning a target system or network to identify potential vulnerabilities. White box testing is a type of penetration testing in which the tester has full knowledge of the target system or network, including source code and network topology.

In conclusion, the correct answer to this question is A. Reconnaissance, which is the phase of penetration testing in which an attacker uses publicly available resources to gather information about the target system or network.