Which of the following is a direct example of data collection during post-exploitation?

Prepare for the eLearnSecurity Junior Penetration Tester exam with our comprehensive quiz platform. Improve your skills with multiple-choice questions, detailed explanations, and exam tips. Get exam ready with ease!

Multiple Choice

Which of the following is a direct example of data collection during post-exploitation?

Explanation:
In post-exploitation, the goal is to gather information from the compromised host to understand the environment and plan next steps like exfiltration or further access. Collecting usernames, system information, and installed software is a direct example of data collection because it pulls concrete data from the machine about who uses it, what OS and versions are in use, and what software is installed. This kind of information is exactly what attackers look for to map the target and decide how to proceed. The other actions describe changes to the system or its defenses rather than collecting data: patching vulnerabilities aims to fix issues (not gather data), deploying new services creates or extends capabilities (not data collection), and blocking traffic with ACLs alters network access (also not data collection).

In post-exploitation, the goal is to gather information from the compromised host to understand the environment and plan next steps like exfiltration or further access. Collecting usernames, system information, and installed software is a direct example of data collection because it pulls concrete data from the machine about who uses it, what OS and versions are in use, and what software is installed. This kind of information is exactly what attackers look for to map the target and decide how to proceed.

The other actions describe changes to the system or its defenses rather than collecting data: patching vulnerabilities aims to fix issues (not gather data), deploying new services creates or extends capabilities (not data collection), and blocking traffic with ACLs alters network access (also not data collection).

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy