Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 100-160 Exam - Topic 2 Question 16 Discussion

You are going to perform a penetration test on a company LAN. As part of your preparation, you access the company's websites, view webpage source code, and run internet searches to uncover domain information. You also use social media to gather details about the company and its employees.Which type of reconnaissance activities are you performing?
A) Passive
B) Active
C) Offline
D) Invasive

Cisco 100-160 Exam - Topic 2 Question 16 Discussion

Actual exam question for Cisco's 100-160 exam
Question #: 16
Topic #: 2
[All 100-160 Questions]

You are going to perform a penetration test on a company LAN. As part of your preparation, you access the company's websites, view webpage source code, and run internet searches to uncover domain information. You also use social media to gather details about the company and its employees.

Which type of reconnaissance activities are you performing?

Show Suggested Answer Hide Answer
Suggested Answer: A

The CCST Cybersecurity Study Guide explains that reconnaissance is the process of collecting information about a target before attempting exploitation.

'Passive reconnaissance is conducted without directly engaging with the target systems. Examples include reviewing public websites, examining HTML source code, querying public DNS records, and using social media to gather information. Since no packets are sent directly to the target system, it reduces the risk of detection.'

(CCST Cybersecurity, Vulnerability Assessment and Risk Management, Reconnaissance Techniques section, Cisco Networking Academy)

Passive (A) is correct because all actions described --- viewing public pages, searching online, and checking social media --- involve no direct interaction that could alert the target.

Active (B) would involve direct probing, like port scans or vulnerability scans.

Offline (C) is not an official reconnaissance classification in this context.

Invasive (D) is a general term and not used as a standard reconnaissance category in CCST material.


Contribute your Thoughts:

0/2000 characters
Willis
3 days ago
Definitely A) Passive. No invasive techniques here, just research.
upvoted 0 times
...
Nan
8 days ago
I still think it's A) Passive. We're just collecting data from public sources.
upvoted 0 times
...
Sommer
13 days ago
But what about B) Active? Running searches feels more hands-on.
upvoted 0 times
...
Salome
19 days ago
I agree, A) Passive makes sense. Just observing, not touching anything.
upvoted 0 times
...
Melda
24 days ago
I'm leaning towards A) Passive. It feels like gathering info without direct interaction.
upvoted 0 times
...
Jose
29 days ago
Totally passive, no direct interaction with the systems.
upvoted 0 times
...
Gayla
1 month ago
Wait, you can get that much from social media? Surprising!
upvoted 0 times
...
Micaela
1 month ago
Seems like a mix, but mostly passive for sure.
upvoted 0 times
...
Vashti
1 month ago
I thought it was active since you're gathering info.
upvoted 0 times
...
Hildegarde
2 months ago
That's definitely passive reconnaissance!
upvoted 0 times
...
Sylvia
2 months ago
I’m a bit confused here. Couldn’t it also be considered active if you’re running searches? But I guess that’s just part of the passive approach.
upvoted 0 times
...
Coletta
2 months ago
I practiced a similar question, and I believe it’s definitely passive since you’re using social media and websites to collect data without probing the network.
upvoted 0 times
...
Willard
2 months ago
I’m not entirely sure, but I remember something about active versus passive. This feels more like passive because you’re just looking at public info.
upvoted 0 times
...
Tijuana
2 months ago
I think this is passive reconnaissance since you're gathering information without directly interacting with the target systems.
upvoted 0 times
...

Save Cancel