An administrator wants to perform a risk assessment without using proprietary company information. Which of the following methods should the administrator use to gather information?
Choose an answer
Tap an option to check your answer.
Correct answer: Open-source intelligence.
Why this is the answer
Open-source intelligence (OSINT) involves collecting information from publicly available sources. This method allows an administrator to gather data relevant to potential threats and vulnerabilities without accessing or exposing proprietary company information, as the data is already public. Network scanning and penetration testing directly interact with the company's internal systems and would involve proprietary information. Configuration auditing also involves examining internal system configurations, which are proprietary.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed