GIAC Certified Incident Handler (GCIH) — Question 170
When would a web-based reconnaissance tool be preferred over a direct/local reconnaissance tool?
Answer options
- A. When more comprehensive TCP port scanning is required than what is offered by local tools
- B. In the event that the target is running third-party web applications
- C. When the target's employees are using a VPN to connect to the central office
- D. To keep traffic from the attacker's system from hitting the target network
Correct answer: C
Explanation
The correct answer, C, is valid because a web-based reconnaissance tool can operate from outside the target's network, effectively bypassing VPN protections. The other options do not necessarily require a web-based approach, as they can be handled using local tools or do not pertain to the need for remote access.