CompTIA Security+ (SY0-701) · Free practice question 8 of 12
Passive reconnaissance from public sources
During the first phase of an authorized assessment of Westray Foods, testers gather employee names from professional networking sites, read the company's job postings and look up public DNS records, without sending any traffic to Westray's systems. What kind of activity is this?
- A.Passive reconnaissance
- B.Active reconnaissance
- C.Privilege escalation
- D.Lateral movement
Show answer and explanation
Correct answer: A. Passive reconnaissance
Why: Passive reconnaissance collects information from public, open sources without interacting directly with the target's systems, so it is hard for the target to detect. Active reconnaissance, such as port scanning, sends traffic to the target. Privilege escalation and lateral movement happen after a foothold is gained.
More free CompTIA Security+ (SY0-701) questions
- Access control vestibule stops tailgating
- Trusted Platform Module characteristics
- Blockchain open public ledger integrity
- Virtual machine escape vulnerability
- Jump server for administrative access
- OAuth delegated authorization without passwords
- Non-disclosure agreement for consultants
- Mean time between failures reliability
- Gap analysis against a framework
- Offline backups for ransomware recovery
- Steganography hiding data in images