Which term describes the initial information-gathering phase conducted by attackers to map an organization before intrusion?

Boost your skills for the EC-Council Certified Ethical Hacker v13 Exam. Use flashcards and multiple choice questions to prepare effectively. Each question includes hints and explanations. Get exam-ready now!

Multiple Choice

Which term describes the initial information-gathering phase conducted by attackers to map an organization before intrusion?

Explanation:
Footprinting is the process of gathering information about a target to map its network, people, and technologies before attempting intrusion. It pulls data from public and sometimes private sources to build a profile of the organization—domain ownership, IP ranges, DNS records, infrastructure, and key personnel—so an attacker can understand the attack surface and plan the next steps. Scanning comes next, focusing on identifying live hosts, open ports, and services on those systems; exfiltration is the act of stealing data from a compromised system; pivoting means moving laterally within the network after gaining access.

Footprinting is the process of gathering information about a target to map its network, people, and technologies before attempting intrusion. It pulls data from public and sometimes private sources to build a profile of the organization—domain ownership, IP ranges, DNS records, infrastructure, and key personnel—so an attacker can understand the attack surface and plan the next steps. Scanning comes next, focusing on identifying live hosts, open ports, and services on those systems; exfiltration is the act of stealing data from a compromised system; pivoting means moving laterally within the network after gaining access.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy