Unnoticed Penetration Testing Techniques

Best Choice for Gathering Useful Data

Prev Question Next Question

Question

While performing a penetration test, the technicians want their efforts to go unnoticed for as long as possible while they gather useful data about the network they are assessing.

Which of the following would be the BEST choice for the technicians?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

C.

Out of the given options, the BEST choice for the technicians to remain unnoticed while gathering useful data about the network they are assessing would be a Packet Sniffer (Option C).

A packet sniffer is a tool that captures and analyzes network traffic in real-time. It can intercept and examine packets of data that are transmitted between devices on the network, without being detected. It can capture all types of network traffic, including unencrypted passwords and sensitive information. By using a packet sniffer, the technicians can gather a wealth of information about the network, including IP addresses, network topology, and protocols in use.

The other options may not be as effective in remaining undetected while gathering useful data. Vulnerability scanner (Option A) is a tool that scans a network for vulnerabilities and can generate a report of all identified vulnerabilities. However, it can be detected by intrusion detection systems (IDS) and may trigger alerts.

An offline password cracker (Option B) is a tool that can be used to crack passwords that have been captured by other means, such as a packet sniffer. It is not useful in remaining undetected while gathering data.

Banner grabbing (Option D) is a technique that involves retrieving information about a service, such as its version number, by sending a request to the service and analyzing the response. It can be detected by intrusion detection systems (IDS) and may trigger alerts.

In summary, the BEST choice for the technicians to remain unnoticed while gathering useful data about the network they are assessing would be a packet sniffer, as it can intercept and examine network traffic without being detected.