Active vs Passive Reconnaissance in Penetration Testing
A penetration tester begins an engagement by performing port and service scans against the client environment according to the rules of engagement. Which of the following reconnaissance types is the tester performing?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the ability to distinguish between observation-based passive methods and interaction-based active methods, with the trap being the assumption that all scanning is stealthy or non-intrusive.
Port and service scans constitute active reconnaissance because they involve direct interaction with target systems. The community consensus confirms that any probing activity generating traffic is classified as active rather than passive.
Option B (Passive) is the most common distractor; candidates may mistakenly believe that scanning is 'stealthy' or 'non-destructive,' failing to recognize that sending packets constitutes active engagement.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Active reconnaissance involves directly interacting with the target system to gather information, such as performing port scans or service identification using tools like Nmap. Since the penetration tester is actively sending probes to the client environment to elicit responses, this fits the definition of active reconnaissance perfectly.Why the Other Options Are Wrong
Passive reconnaissance (B) involves gathering data without touching the target, such as using WHOIS, DNS records, or social media. Defensive (C) refers to security measures protecting assets, not a testing phase. Offensive (D) is a broad term for the entire attack phase but does not specifically describe the reconnaissance methodology defined by the level of interaction.Community Comment Notes
Comment [1] and [4] provide excellent definitions distinguishing active scanning from passive OSINT techniques. Comment [5] correctly identifies Nmap as an example of active scanning, reinforcing the link between specific tools and their classification.Official Reference
Exam Strategy
Focus on the keyword 'interaction.' If the tester sends packets, queries, or requests to the target, it is Active. If they only observe public data or network traffic without sending anything new, it is Passive.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →