34. At the start of a penetration test, the tester checks OSINT resources for information about the client environment. Which of the following types of reconnaissance is the tester performing?

Answer: B

Explanation:

Passive reconnaissance is being performed.

The tester is engaging in passive reconnaissance by utilizing OSINT (Open Source Intelligence) resources to gather information about the client environment without actively interacting with the target systems.

A) Active

Active reconnaissance involves directly interacting with the target systems to gather information, such as network scanning or probing services. Since the tester is using OSINT resources without direct engagement, this option is incorrect.

B) Passive

Passive reconnaissance is characterized by collecting information from publicly available sources without alerting the target. By using OSINT, the tester is effectively gathering data without triggering any defenses or making their presence known, making this the correct option.

C) Offensive

Offensive reconnaissance typically refers to strategies that involve direct actions aimed at exploiting vulnerabilities. This does not apply here as the tester is not taking aggressive actions but rather gathering information quietly, thus making this option incorrect.

D) Defensive

Defensive reconnaissance would imply actions taken to protect against potential attacks or to analyze threats to the organization. Since the tester's focus is on gathering information about the client environment for potential exploitation, this option does not fit the scenario and is therefore incorrect.

Conclusion

Passive reconnaissance is the correct choice because it accurately describes the method used by the tester to gather information from OSINT sources without active engagement. All other options misrepresent the nature of the reconnaissance being performed, either by suggesting direct interaction or misaligning the intent of the activity.