Courseiva
Security Operations →mediumMultiple Select

CAS-004 Security Operations Practice Question

A security analyst is conducting a penetration test for a client. The rules of engagement specify that no social engineering is allowed. Which TWO of the following reconnaissance techniques are permitted under these rules?

⚠ Common exam trap

The trap here is conflating 'reconnaissance' with 'social engineering' — candidates may think any information-gathering technique is off-limits, but the RoE only prohibits social engineering, so technical scanning and public DNS enumeration remain permitted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scanning the client's external network for open ports

Option B is correct because scanning the client's external network for open ports is a purely technical reconnaissance activity that does not involve deceiving or manipulating people, so it falls outside the prohibition on social engineering. Option C is correct because DNS enumeration using public records relies on openly available registration and name-resolution data (e.g., WHOIS, zone data, public DNS queries) rather than human interaction or deception. Option A is not permitted because calling the help desk to obtain credentials is a pretexting/social-engineering attack that manipulates a person into disclosing sensitive information. Option D is not permitted because phishing emails are a classic social-engineering technique that deceives employees into revealing data or executing actions. Option E is not permitted because tailgating is a physical social-engineering method that exploits human trust to gain unauthorized building access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Calling the help desk to obtain credentials

    Why it's wrong here

    Pretexting as a help-desk caller to extract credentials is social engineering, which the rules of engagement explicitly forbid. It is tempting because help-desk impersonation is a standard reconnaissance tactic, and it would be permitted in engagements whose scope authorises social-engineering testing against staff.

  • ✓

    Scanning the client's external network for open ports

    Why this is correct

    Scanning external networks for open ports is a technical reconnaissance activity that does not involve deceiving or manipulating people, so it satisfies the rules of engagement prohibiting social engineering. It maps the attack surface through direct network probing rather than human interaction, making it permissible alongside other non-social techniques.

  • ✓

    Performing DNS enumeration using public records

    Why this is correct

    DNS enumeration using public records queries registries and resolvers rather than client personnel, so no pretexting or deception occurs. It stays within the rules of engagement because the social engineering restriction only prohibits manipulating people.

  • ✗

    Sending phishing emails to employees

    Why it's wrong here

    Phishing employees is social engineering, directly violating the stated prohibition. It is tempting because phishing is a common initial-access technique in penetration tests, and it would be the correct choice only where the rules of engagement explicitly authorise social-engineering campaigns against the client's users.

  • ✗

    Tailgating into the building

    Why it's wrong here

    Tailgating is a physical social-engineering technique: following an authorised person through a secure door exploits human trust, so the no-social-engineering rule prohibits it. It is tempting because physical access is a legitimate penetration-test objective, and tailgating would be valid where the rules of engagement permit physical intrusion attempts.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.