A security analyst wants to gather information about a target domain using publicly available sources without directly interacting with the target’s systems. Which type of reconnaissance is being performed?
Passive reconnaissance gathers information solely from publicly available sources, such as search engines, WHOIS records and cached pages, without sending any traffic to the target's systems. This satisfies the stem's constraint of no direct interaction, unlike active reconnaissance, which probes the target and risks detection.
Why this answer
Passive reconnaissance involves collecting information about a target from publicly available sources without sending any packets or making direct contact with the target's systems. This approach relies on open-source intelligence (OSINT) such as WHOIS records, DNS lookups, search engines, and social media, ensuring no footprint is left on the target's network.
Exam trap
The trap here is confusing passive reconnaissance with active reconnaissance; candidates often think any information gathering is 'active' because it involves tools, but the key distinction is whether the target's systems are directly contacted (active) or not (passive).
How to eliminate wrong answers
Option A is wrong because vulnerability scanning is an active process that sends probes (e.g., SYN packets, HTTP requests) to identify weaknesses, directly interacting with target systems. Option B is wrong because social engineering involves manipulating people to divulge information, which requires direct interaction (e.g., phishing emails, phone calls) and is not a reconnaissance technique based solely on public sources. Option C is wrong because active reconnaissance involves direct engagement with the target's systems (e.g., port scanning with Nmap, banner grabbing), generating traffic that can be logged or detected.