A security analyst discovers that an attacker used a publicly available tool to scan a company's network for open ports and services. What type of attack is this?
Active reconnaissance involves directly interacting with target systems, such as port scanning with tools like Nmap, generating traffic the target can detect. This matches the stem's constraint of using a publicly available tool to scan for open ports and services.
Why this answer
Using a publicly available tool to scan a company's network for open ports and services involves directly interacting with the target systems by sending probes (e.g., TCP SYN packets, UDP datagrams) and analyzing responses. This constitutes active reconnaissance, as the attacker's actions generate traffic that can be detected by intrusion detection systems (IDS) or firewall logs, unlike passive methods that only observe existing traffic.
Exam trap
Cisco often tests the distinction between active and passive reconnaissance by presenting a scenario where a tool is used to 'scan' or 'probe' the network, and candidates mistakenly choose passive reconnaissance because they think 'scanning' is non-intrusive, but any direct interaction with the target (sending packets) is active.
How to eliminate wrong answers
Option A is wrong because passive reconnaissance involves gathering information without directly interacting with the target network, such as sniffing traffic or using public records (e.g., WHOIS, DNS lookups), not sending probes to identify open ports. Option B is wrong because a Denial of Service (DoS) attack aims to disrupt or degrade service availability by overwhelming resources (e.g., SYN flood, ICMP flood), not to enumerate open ports and services for later exploitation. Option C is wrong because social engineering exploits human psychology to manipulate individuals into divulging confidential information or performing actions, not technical scanning of network ports and services.