CompTIA PenTest+ (PT0-002) — Question 260
During passive reconnaissance of a target organization’s infrastructure, a penetration tester wants to identify key contacts and job responsibilities within the company. Which of the following techniques would be the most effective for this situation?
Answer options
- A. Social media scraping
- B. Website archive and caching
- C. DNS lookup
- D. File metadata analysis
Correct answer: A
Explanation
Social media scraping is the most effective technique in this case, as it allows the tester to gather information about key personnel and their roles directly from platforms where employees may share professional details. The other options, such as website archive and caching, DNS lookup, and file metadata analysis, may provide useful information but are less focused on identifying individual contacts and their job responsibilities.