Testers enumerate encryption modes on city SSIDs and probe open management ports on wireless controllers before any exploitation attempts. Which pen-test phase is this?
Select an answer to reveal the explanation.
Short Explanation
Scanning is the methodical knock-and-listen step—what crypto is on each SSID, which controller ports answer—before anyone tries to break in. Skip it and you are swinging blind in city hall’s RF closet.
Full Explanation
The scanning phase identifies technical details such as encryption/AKM modes and exposed services on WLAN infrastructure prior to exploitation. It is a distinct step after information gathering and before in-scope attack techniques. Jamming-first or undocumented hallway debriefs are not substitutes for scanning.