CAS-004 Security Operations Practice Question
A security analyst is conducting a penetration test for a client. The rules of engagement specify that no social engineering is allowed. Which TWO of the following reconnaissance techniques are permitted under these rules?
⚠ Common exam trap
The trap here is conflating 'reconnaissance' with 'social engineering' — candidates may think any information-gathering technique is off-limits, but the RoE only prohibits social engineering, so technical scanning and public DNS enumeration remain permitted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Scanning the client's external network for open ports
Option B is correct because scanning the client's external network for open ports is a purely technical reconnaissance activity that does not involve deceiving or manipulating people, so it falls outside the prohibition on social engineering. Option C is correct because DNS enumeration using public records relies on openly available registration and name-resolution data (e.g., WHOIS, zone data, public DNS queries) rather than human interaction or deception. Option A is not permitted because calling the help desk to obtain credentials is a pretexting/social-engineering attack that manipulates a person into disclosing sensitive information. Option D is not permitted because phishing emails are a classic social-engineering technique that deceives employees into revealing data or executing actions. Option E is not permitted because tailgating is a physical social-engineering method that exploits human trust to gain unauthorized building access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Calling the help desk to obtain credentials
Why it's wrong here
Pretexting as a help-desk caller to extract credentials is social engineering, which the rules of engagement explicitly forbid. It is tempting because help-desk impersonation is a standard reconnaissance tactic, and it would be permitted in engagements whose scope authorises social-engineering testing against staff.
- ✓
Scanning the client's external network for open ports
Why this is correct
Scanning external networks for open ports is a technical reconnaissance activity that does not involve deceiving or manipulating people, so it satisfies the rules of engagement prohibiting social engineering. It maps the attack surface through direct network probing rather than human interaction, making it permissible alongside other non-social techniques.
- ✓
Performing DNS enumeration using public records
Why this is correct
DNS enumeration using public records queries registries and resolvers rather than client personnel, so no pretexting or deception occurs. It stays within the rules of engagement because the social engineering restriction only prohibits manipulating people.
- ✗
Sending phishing emails to employees
Why it's wrong here
Phishing employees is social engineering, directly violating the stated prohibition. It is tempting because phishing is a common initial-access technique in penetration tests, and it would be the correct choice only where the rules of engagement explicitly authorise social-engineering campaigns against the client's users.
- ✗
Tailgating into the building
Why it's wrong here
Tailgating is a physical social-engineering technique: following an authorised person through a secure door exploits human trust, so the no-social-engineering rule prohibits it. It is tempting because physical access is a legitimate penetration-test objective, and tailgating would be valid where the rules of engagement permit physical intrusion attempts.
Visual reference
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.