QuestionQ339

Engagement Management

A company engages a penetration tester to conduct an external attack-surface review as part of a security engagement. The company tells the tester that the primary company domain to investigate is comptia.org. Which action should the tester take to meet the assessment objective?

  • A Perform information-gathering techniques to review internet-facing assets for the company.
  • B Perform a phishing assessment to try to gain access to more resources and users’ computers.
  • C Perform a physical security review to identify vulnerabilities that could affect the company.
  • D Perform a vulnerability assessment over the main domain address provided by the client.
Explanation

An external attack-surface review requires reconnaissance and information gathering to identify and examine the organization’s internet-facing assets associated with its domain.

Community Discussion

No comments yet. Be the first to start the discussion!