header bg

Question:

Sally is a member of a pen test team that was recently engaged to test the security of a bank. She starts by scanning public data on the Internet for IP addresses that the bank may own. She also searches for news stories and job advertisements to find information that may be useful. What stage of the pen test is Sally working on?

A Evaluation
Explaination

The evaluation phase, which EC-Council also refers to alternatively as the "conduct" phase, is when all of the action occurs, including the passive information collection conducted by Sally in this case.