What Is a Common Passive Reconnaissance Technique Used by Pen Testers?

Which of the following is a common, passive reconnaissance technique employed by penetration testers in the early phases of an engagement?

  1. Open-source intelligence Source Reference Answer
  2. Port scanning
  3. Pivoting
  4. Exploit validation

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the difference between passive and active reconnaissance; the trap is seeing 'reconnaissance' and choosing port scanning, which is active, not passive.

Open-source intelligence (OSINT) is a common passive reconnaissance technique used by penetration testers to gather publicly available information without directly interacting with target systems. Community consensus overwhelmingly identifies OSINT as the correct answer for this early-engagement phase.

Port scanning (B) is the most common wrong answer because it is a well-known recon technique, but it actively sends packets to the target, making it the opposite of passive OSINT.

Community Discussion (4 comments)

a4e15bd 👍 2 Selected: A
correct answer if A. OSINT
850bc48 👍 2
Chat GPT: The correct answer is A. Open-source intelligence (OSINT). OSINT is a common passive reconnaissance technique where penetration testers gather information from publicly available sources, such as websites, social media, and databases, without directly interacting with the target systems. This helps them learn more about the target while minimizing the chances of detection. Options B, C, and D involve more active techniques, which usually come later in the penetration testing process: B. Port scanning is an active technique to identify open ports and services on a target. C. Pivoting refers to using a compromised system to gain access to other systems within a network. D. Exploit validation involves testing vulnerabilities to confirm whether they can be successfully exploited.
abbey0922 👍 1 Selected: A
Passive reconnaissance gathers information about the target system without contacting it directly. An open source intelligence (OSINT) investigation can discover publicly available information about the target system. The utility of such information depends on the type of penetration test
Cee007 👍 1 Selected: A
A. Open-source intelligence (OSINT) OSINT involves gathering information from publicly available sources, such as social media, websites, and online databases, without actively interacting with the target system. This technique helps in identifying potential vulnerabilities and understanding the target's environment before more intrusive methods are used.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Open-source intelligence (OSINT) is the only option that is inherently passive. It involves collecting data from public sources such as websites, social media, and registries without sending packets to the target. Community commenter [1] noted that OSINT "gathers information from publicly available sources... without directly interacting with the target systems," which minimizes detection.

Why the Other Options Are Wrong

Port scanning (B) actively sends packets to target hosts to discover open ports and services, so it is active reconnaissance. Pivoting (C) is a post-exploitation technique used to move through a compromised network, not an early reconnaissance step. Exploit validation (D) is part of the exploitation phase, not passive recon. Commenter [2] clearly separated passive OSINT from other options, and commenter [4] confirmed "correct answer if A."

Community Comment Notes

The community overwhelmingly selected A, with all votes (100%) and comments supporting OSINT. Commenter [1] emphasized the "early phases" aspect, while commenter [3] highlighted how OSINT helps identify vulnerabilities before "more intrusive methods are used." There was no dissent or alternative answer, so the consensus is strong.

Official Reference

Exam Strategy

When distinguishing passive vs active recon, ask whether the technique involves direct interaction with the target. If it does, it cannot be passive; OSINT relies solely on publicly accessible information and is the safest early-phase approach.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide