CAS-004 Security Operations Practice Question
A penetration tester is planning a test against a web application. The rules of engagement specify that the tester must not disrupt production services. Which TWO reconnaissance techniques are considered passive and would be appropriate for initial information gathering without impacting the target? (Select TWO.)
⚠ Common exam trap
The trap here is conflating 'non-intrusive' with 'passive' — candidates often pick vulnerability scanning because it can be run in a low-impact mode, but any technique that sends packets to the target is active by definition.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WHOIS lookup on the domain
WHOIS lookup on the domain (D) is correct because it queries public registrar databases for registration details such as registrant contacts, name servers, and creation/expiration dates, generating no traffic to the target's own infrastructure and thus causing zero disruption. OSINT gathering from public sources (E) is correct because it collects information from third-party sites, search engines, cached pages, and public records, again without sending packets to the target and therefore remaining passive and non-disruptive. Port scanning (A) is not passive: it sends TCP/UDP probes (e.g., SYN or connect scans) directly to target hosts, which can be logged, rate-limited, or destabilize fragile services. Vulnerability scanning (B) is also active and intrusive, as it transmits crafted requests and payloads that can crash or overload production systems. Social engineering attacks (C) are neither passive reconnaissance nor non-disruptive, since they involve direct interaction with personnel and can cause operational or security incidents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Port scanning the target network
Why it's wrong here
Port scanning sends packets directly to target hosts, creating connections and log entries, so it is active reconnaissance that can disturb production services. It would be appropriate once passive gathering is complete and active probing is authorised.
- ✗
Vulnerability scanning
Why it's wrong here
Vulnerability scanning sends crafted probes directly to target hosts, consuming resources and risking service disruption, which breaches the no-disruption rule of engagement. It is tempting because scanning genuinely identifies exploitable weaknesses, and it would be the right choice once passive reconnaissance has mapped the attack surface and active testing is explicitly authorised.
- ✗
Social engineering attacks
Why it's wrong here
Social engineering attacks target people rather than the application, breaching the rules of engagement by manipulating staff and risking production disruption. It is tempting because social engineering is genuinely passive towards the target's technical infrastructure, and would suit an engagement scoped to assess human factors or physical security alongside technical testing.
- ✓
WHOIS lookup on the domain
Why this is correct
A WHOIS lookup queries public registrar databases rather than the target's own infrastructure, so no packets reach the web application and production services remain untouched. This satisfies the rules of engagement constraint prohibiting disruption, making it suitable for initial passive information gathering before any active enumeration begins.
- ✓
OSINT gathering from public sources
Why this is correct
OSINT gathering collects information from third-party public sources such as search engines, social media and public records, generating no traffic to the target. This satisfies the rules of engagement requiring passive reconnaissance that cannot disrupt production services.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.