Topic 1 Question #5
A penetration tester is conducting reconnaissance for an upcoming assessment of a large corporate client. The client authorized spear phishing in the rules of engagement. Which of the following should the tester do first when developing the phishing campaign?
- A.
Shoulder surfing
- B.
Recon-ng
- C.
Social media
- D.
Password dumps
Answer: C
The CompTIA PenTest+ (PT0-003) Information Gathering and Vulnerability Assessment domain emphasizes that targeted social engineering campaigns such as spear phishing require prior passive reconnaissance to develop credible, tailored lures. Unlike generic mass phishing, spear phishing targets specific individuals or groups within the client organization, so the first step in campaign development is gathering personal, role-specific, and organizational context to make phishing communications appear legitimate. Reviewing social media profiles is the highest-yield first step for this task, as it provides data on job roles, internal project names, colleague relationships, communication styles, and personal interests that can be used to craft convincing lures that are far more likely to succeed than generic messages, without risking early detection by the client's security controls. Option Analysis:
A. Shoulder surfing: Incorrect. Shoulder surfing is a physical social engineering tactic that requires the tester to be physically present near targets to observe their screens or keystrokes. It is not a first step for developing a phishing campaign, which is typically designed during initial remote reconnaissance before any on-site activities are conducted, and it does not provide the broad context needed to craft targeted lures for multiple spear phishing recipients.
B. Recon-ng: Incorrect. Recon-ng is an automated open-source intelligence (OSINT) aggregation tool that can scrape data from multiple sources including social media platforms. However, it is a tool used to streamline data gathering, not a core first activity itself. PT0-003 domain knowledge emphasizes that testers first identify high-value OSINT sources (like social media) to understand what data is available before deploying automated tools, and direct social media review provides immediate actionable context for lure design faster than setting up and running automated Recon-ng scans.
C. Social media: Correct. Social media is a passive, low-risk OSINT source that provides the targeted personal and organizational context required to design credible spear phishing lures. PT0-003 objectives prioritize passive OSINT gathering first in reconnaissance, and social media is the most relevant first step for spear phishing campaign development because it directly enables the tailored messaging that defines successful spear phishing operations.
D. Password dumps: Incorrect. Password dumps are sets of compromised credentials from past public data breaches. While they may be used later in a phishing campaign to add credibility (e.g., referencing a known past password to trick targets into believing a communication is legitimate) or for post-phishing credential stuffing, they are not a first step. Testers must first identify their target list and design the core lure before integrating breach data into the campaign, if at all. Key Concepts:
1. Spear Phishing Target Profiling: PT0-003 tests knowledge that spear phishing success depends on targeted, personalized messaging, which requires pre-campaign OSINT to collect context on individual targets, their roles, and their organizational environment.
2. Passive OSINT Prioritization: PenTest+ requires understanding that passive OSINT sources, which do not involve direct interaction with the target or target systems and eliminate risk of detection, should be leveraged first during reconnaissance, before active scanning, tool usage, or physical activities.
3. Phishing Campaign Development Lifecycle: The first phase of authorized phishing campaign development per PT0-003 objectives is target enumeration and lure design, which relies on high-quality contextual data before any execution or tool deployment steps. References:
CompTIA PenTest+ (PT0-003) Exam Objectives, SANS Social Engineering Penetration Testing Step-by-Step Guide