What Is a Common Passive Reconnaissance Technique Used by Pen Testers?
Which of the following is a common, passive reconnaissance technique employed by penetration testers in the early phases of an engagement?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the difference between passive and active reconnaissance; the trap is seeing 'reconnaissance' and choosing port scanning, which is active, not passive.
Open-source intelligence (OSINT) is a common passive reconnaissance technique used by penetration testers to gather publicly available information without directly interacting with target systems. Community consensus overwhelmingly identifies OSINT as the correct answer for this early-engagement phase.
Port scanning (B) is the most common wrong answer because it is a well-known recon technique, but it actively sends packets to the target, making it the opposite of passive OSINT.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Open-source intelligence (OSINT) is the only option that is inherently passive. It involves collecting data from public sources such as websites, social media, and registries without sending packets to the target. Community commenter [1] noted that OSINT "gathers information from publicly available sources... without directly interacting with the target systems," which minimizes detection.Why the Other Options Are Wrong
Port scanning (B) actively sends packets to target hosts to discover open ports and services, so it is active reconnaissance. Pivoting (C) is a post-exploitation technique used to move through a compromised network, not an early reconnaissance step. Exploit validation (D) is part of the exploitation phase, not passive recon. Commenter [2] clearly separated passive OSINT from other options, and commenter [4] confirmed "correct answer if A."Community Comment Notes
The community overwhelmingly selected A, with all votes (100%) and comments supporting OSINT. Commenter [1] emphasized the "early phases" aspect, while commenter [3] highlighted how OSINT helps identify vulnerabilities before "more intrusive methods are used." There was no dissent or alternative answer, so the consensus is strong.Official Reference
Exam Strategy
When distinguishing passive vs active recon, ask whether the technique involves direct interaction with the target. If it does, it cannot be passive; OSINT relies solely on publicly accessible information and is the safest early-phase approach.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →