A penetration tester is performing reconnaissance against a target. Which TWO of the following are examples of active reconnaissance? (Select TWO.)
Banner grabbing sends crafted requests directly to target services and reads their responses, so the tester's traffic reaches the target's systems. That interaction with the target distinguishes active reconnaissance from passive methods such as OSINT or DNS lookups, which never touch the target directly.
Why this answer
Banner grabbing (A) is active reconnaissance because the tester directly connects to target services (e.g., via netcat or telnet to a port) and reads the service's response banner, which generates traffic and can be logged by the target. Port scanning (C) is also active reconnaissance since tools like Nmap send TCP SYN, TCP connect, or UDP probes directly to the target's IP addresses to discover open ports, again interacting with the target's systems. In contrast, social media profiling (B), WHOIS lookup (D), and searching job postings (E) are passive reconnaissance techniques that rely on publicly available third-party information without directly touching the target's infrastructure, so they do not qualify as active reconnaissance.
Exam trap
The trap is confusing passive OSINT techniques (WHOIS, social media) with active probing; candidates may incorrectly select D or E as active.