ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 258 - PT0-002 discussion

Report
Export

A penetration tester is conducting an engagement against an internet-facing web application and planning a phishing campaign. Which of the following is the BEST passive method of obtaining the technical contacts for the website?

A.
WHOIS domain lookup
Answers
A.
WHOIS domain lookup
B.
Job listing and recruitment ads
Answers
B.
Job listing and recruitment ads
C.
SSL certificate information
Answers
C.
SSL certificate information
D.
Public data breach dumps
Answers
D.
Public data breach dumps
Suggested answer: A

Explanation:

The BEST passive method of obtaining the technical contacts for the website would be a WHOIS domain lookup. WHOIS is a protocol that provides information about registered domain names, such as the registration date, registrant's name and contact information, and the name servers assigned to the domain. By performing a WHOIS lookup, the penetration tester can obtain the contact information of the website's technical staff, which can be used to craft a convincing phishing email.

asked 02/10/2024
Igor Komino
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first