exam questions

Exam PT0-002 All Questions

View all questions & answers for the PT0-002 exam

Exam PT0-002 topic 1 question 114 discussion

Actual exam question from CompTIA's PT0-002
Question #: 114
Topic #: 1
[All PT0-002 Questions]

A security firm has been hired to perform an external penetration test against a company. The only information the firm received was the company name. Which of the following passive reconnaissance approaches would be MOST likely to yield positive initial results?

  • A. Specially craft and deploy phishing emails to key company leaders.
  • B. Run a vulnerability scan against the company's external website.
  • C. Runtime the company's vendor/supply chain.
  • D. Scrape web presences and social-networking sites.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
nickwen007
8 months ago
D is the most likely to yield positive initial results. Scraping web presences and social-networking sites can provide information about a company such as its address, size, services, customer reviews, and contact information. This can be useful when starting a penetration test. Specially crafting and deploying phishing emails to key company leaders is not recommended, as it can be easily detected and flagged as malicious activity. Running a vulnerability scan against the company's external website can reveal vulnerable services or applications, but is not likely to yield much useful information. Lastly, researching the company's vendor/supply chain may provide some useful insights, but it is not likely to be the most effective starting point.
upvoted 3 times
...
kloug
8 months, 2 weeks ago
ddddddddddddd
upvoted 2 times
...
NotAHackerJustYet
9 months, 1 week ago
Selected Answer: D
Option A is incorrect because phishing emails are not a good approach for initial information gathering. Phishing emails are used to gain access to a company's internal systems and data, but they are not an effective way to gather information about a company's external presence. Option B is incorrect because running a vulnerability scan against the company's external website is not a passive approach. Vulnerability scans involve actively probing a system and are better suited for internal penetration tests. Option C is incorrect because running the company's vendor/supply chain is not a passive approach. This approach could potentially yield some information, but it is not the most effective way to gather initial information.
upvoted 4 times
...
Codyjs54
9 months, 1 week ago
Selected Answer: D
It is D. Read it carefully
upvoted 3 times
...
shakevia463
9 months, 1 week ago
Selected Answer: D
This is the first step gathering public and social information
upvoted 3 times
...
ronniehaang
10 months, 3 weeks ago
Selected Answer: D
Social media scraping - Key contacts/job responsibilities - Job listing/technology stack
upvoted 3 times
...
Neolot
1 year, 1 month ago
I think the answer to this is D. You'll get to do C after doing it.
upvoted 4 times
Hskwkhfb
11 months, 2 weeks ago
Why not b?
upvoted 1 times
Mr_BuCk3th34D
10 months, 3 weeks ago
Because it says "passive reconnaissance"
upvoted 2 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago