A consultant proposes “wireless OSINT” for the library that consists of capturing handshakes and running aircrack-class attacks against guest and staff networks. How should the PORP candidate classify that work?
Select an answer to reveal the explanation.
Short Explanation
If the pitch is “capture a handshake and crack the library,” that is a pentest sibling, not PORP. Public building or guest SSID does not change the method. Deauthing patrons is not a kinder version of research either.
Full Explanation
PORP wireless OSINT is observation of public artifacts and datasets. Handshake capture and aircrack-class key recovery are offensive wireless techniques associated with other credentials, not with PORP, and public-building status or a guest SSID does not convert cracking into OSINT. Deauthentication is also an attack. The candidate should refuse the method, keep collection on public SSID/BSSID/map observations, and refer any authorized wireless assessment to the appropriate engagement type.