Occupancy licensing profiles a contractor website and learns the CMS type. Staff want to treat that output as a vulnerability to attack. How should the analyst treat it?
Select an answer to reveal the explanation.
Short Explanation
Seeing the shop sign is not kicking in the door. A CMS fingerprint is a description for the notes, not a pentest plan. PORP records the stack; it does not exploit it.
Full Explanation
Website-tech profilers support OSINT by describing public stack clues such as CMS family. In PORP that output is a fingerprint for vendor due diligence and correlation, not a lead to exploit. Unauthorized access and credential guessing belong to pentest credentials. Descriptive website OSINT remains in scope; exploitation does not.