Active vs Passive Reconnaissance in Penetration Testing

Penetration Testing Methodologies

A penetration tester begins an engagement by performing port and service scans against the client environment according to the rules of engagement. Which of the following reconnaissance types is the tester performing?

  1. Active Source Reference Answer
  2. Passive
  3. Defensive
  4. Offensive

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the ability to distinguish between observation-based passive methods and interaction-based active methods, with the trap being the assumption that all scanning is stealthy or non-intrusive.

Port and service scans constitute active reconnaissance because they involve direct interaction with target systems. The community consensus confirms that any probing activity generating traffic is classified as active rather than passive.

Option B (Passive) is the most common distractor; candidates may mistakenly believe that scanning is 'stealthy' or 'non-destructive,' failing to recognize that sending packets constitutes active engagement.

Community Discussion (7 comments)

shady23 👍 18 Selected: A
A. Active Active reconnaissance involves actively probing and scanning the target environment to gather information. This typically includes activities such as port and service scans, vulnerability scans, and other direct interactions with the target systems to identify potential weaknesses or entry points. Passive reconnaissance, on the other hand, involves gathering information without directly interacting with the target systems, such as monitoring network traffic or analyzing publicly available information. Options C and D, defensive and offensive reconnaissance, respectively, are not standard reconnaissance types typically used in the context of penetration testing.
JackExam2025 👍 1 Selected: A
Interacting with the target systems, the reconnaissance type is active
EngAbood 👍 1 Selected: A
Active for sure :)
dbrowndiver 👍 2 Selected: A
Active reconnaissance involves directly interacting with the target systems to gather information. This type of reconnaissance is often more intrusive because it sends packets or requests to the target to elicit responses, allowing the tester to gather detailed information about the target's configuration and potential weaknesses. In this Scenario Application: Direct Interaction: By performing port and service scans, the tester is "actively" sending packets to the target systems to determine which ports are open and what services are running. This direct interaction is characteristic of active reconnaissance. Used for Detailed Information Gathering: Active reconnaissance allows the Pen tester to gather precise details about the target's network, such as identifying specific services, versions, and potential entry points for further testing. This is why it pertains and fits: The nature of port and service scanning, which involves direct communication with the target systems, is aligned with the concept of active reconnaissance. It aims to provide a clear understanding of the target's network infrastructure and potential vulnerabilities.
PAWarriors 👍 1 Selected: A
Correct answer is A. Active Reconnaissance: Engaging with the target system directly, such as scanning for open ports using tools like Nmap. Passive Reconnaissance: Gathering information without direct engagement, like using open-source intelligence or WHOIS to collect data
MAKOhunter33333333 👍 3 Selected: A
NMAP is an active scan.
Yoez 👍 3
Correct Answer: A

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Active reconnaissance involves directly interacting with the target system to gather information, such as performing port scans or service identification using tools like Nmap. Since the penetration tester is actively sending probes to the client environment to elicit responses, this fits the definition of active reconnaissance perfectly.

Why the Other Options Are Wrong

Passive reconnaissance (B) involves gathering data without touching the target, such as using WHOIS, DNS records, or social media. Defensive (C) refers to security measures protecting assets, not a testing phase. Offensive (D) is a broad term for the entire attack phase but does not specifically describe the reconnaissance methodology defined by the level of interaction.

Community Comment Notes

Comment [1] and [4] provide excellent definitions distinguishing active scanning from passive OSINT techniques. Comment [5] correctly identifies Nmap as an example of active scanning, reinforcing the link between specific tools and their classification.

Official Reference

Exam Strategy

Focus on the keyword 'interaction.' If the tester sends packets, queries, or requests to the target, it is Active. If they only observe public data or network traffic without sending anything new, it is Passive.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide