Courseiva
Security Operations →easyMultiple Select

CAS-004 Security Operations Practice Question

A penetration tester is planning a test against a web application. The rules of engagement specify that the tester must not disrupt production services. Which TWO reconnaissance techniques are considered passive and would be appropriate for initial information gathering without impacting the target? (Select TWO.)

⚠ Common exam trap

The trap here is conflating 'non-intrusive' with 'passive' — candidates often pick vulnerability scanning because it can be run in a low-impact mode, but any technique that sends packets to the target is active by definition.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WHOIS lookup on the domain

WHOIS lookup on the domain (D) is correct because it queries public registrar databases for registration details such as registrant contacts, name servers, and creation/expiration dates, generating no traffic to the target's own infrastructure and thus causing zero disruption. OSINT gathering from public sources (E) is correct because it collects information from third-party sites, search engines, cached pages, and public records, again without sending packets to the target and therefore remaining passive and non-disruptive. Port scanning (A) is not passive: it sends TCP/UDP probes (e.g., SYN or connect scans) directly to target hosts, which can be logged, rate-limited, or destabilize fragile services. Vulnerability scanning (B) is also active and intrusive, as it transmits crafted requests and payloads that can crash or overload production systems. Social engineering attacks (C) are neither passive reconnaissance nor non-disruptive, since they involve direct interaction with personnel and can cause operational or security incidents.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Port scanning the target network

    Why it's wrong here

    Port scanning sends packets directly to target hosts, creating connections and log entries, so it is active reconnaissance that can disturb production services. It would be appropriate once passive gathering is complete and active probing is authorised.

  • ✗

    Vulnerability scanning

    Why it's wrong here

    Vulnerability scanning sends crafted probes directly to target hosts, consuming resources and risking service disruption, which breaches the no-disruption rule of engagement. It is tempting because scanning genuinely identifies exploitable weaknesses, and it would be the right choice once passive reconnaissance has mapped the attack surface and active testing is explicitly authorised.

  • ✗

    Social engineering attacks

    Why it's wrong here

    Social engineering attacks target people rather than the application, breaching the rules of engagement by manipulating staff and risking production disruption. It is tempting because social engineering is genuinely passive towards the target's technical infrastructure, and would suit an engagement scoped to assess human factors or physical security alongside technical testing.

  • ✓

    WHOIS lookup on the domain

    Why this is correct

    A WHOIS lookup queries public registrar databases rather than the target's own infrastructure, so no packets reach the web application and production services remain untouched. This satisfies the rules of engagement constraint prohibiting disruption, making it suitable for initial passive information gathering before any active enumeration begins.

  • ✓

    OSINT gathering from public sources

    Why this is correct

    OSINT gathering collects information from third-party public sources such as search engines, social media and public records, generating no traffic to the target. This satisfies the rules of engagement requiring passive reconnaissance that cannot disrupt production services.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.