Section 13.119 Reconnaissance in Pentesting Flashcards

Objective 5.5 Explain types and purposes of audits and assessments

1
Q

Reconnaissance

A

Initial phase where an attacker gathers information about the target system. This information helps plan the attack and increase its success rate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Importance of Reconnaissance

A

Crucial step in penetration testing which identifies potential vulnerabilities in the target system

■ Helps plan the attack to reduce the risk of detection and failure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Types of Reconnaissance

Active Reconnaissance

A

Engaging with the target system directly, such as scanning for open ports using tools like Nmap

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Types of Reconnaissance

Passive Reconnaissance

A

Gathering information without direct engagement, like using open-source
intelligence or WHOIS to collect data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Reconnaissance and Environment Types

Known Environment

A

Penetration testers have detailed information about the target infrastructure

● Focuses on known assets
● Evaluates vulnerabilities and weaknesses
● Aims to understand exploitability and potential damages
● Resembles an insider threat scenario

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Reconnaissance and Environment Types

Partially Known Environment

A

Testers have limited information, simulating a scenario where an attacker
has partial inside knowledge

● Focus on discovering and navigating the broader environment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Reconnaissance and Environment Types

Unknown Environment

A

Minimal to no information about the target system

● Simulates a real-world external attacker aiming to find entry points and
vulnerabilities

● Extensive reconnaissance is essential

How well did you know this?
1
Not at all
2
3
4
5
Perfectly