Reconnaissance
Reconnaissance is the process of gathering information about a target system before performing a security assessment or attack.
“The exploration of a target area aiming to gain information that can be useful for an attack.”
(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)
View the complete ISTQB GlossaryWhat is Reconnaissance?
Security professionals collect publicly available and technical information to understand the target's infrastructure, technologies, and potential attack surface.
Information gathering: Collects technical and organizational details.
Preparation phase: Supports effective security assessments.
Attack surface analysis: Identifies possible entry points.
Real World Example
A regulated product team is preparing a release where Reconnaissance appears in reviews, test design conversations, or defect triage rather than as an isolated glossary word.
The risk is that the team treats Reconnaissance as interchangeable with nearby ISTQB terms. That makes test scope blurry and can lead to weak evidence for the release decision.
The tester anchors the discussion in the official definition, asks where the concept appears in the product, and designs examples that show the difference between Reconnaissance and similar ideas.
The page becomes useful in practice because Reconnaissance is connected to a specific testing decision, not memorized as a detached definition.
Practice Questions
Question 1
Which statement BEST describes Reconnaissance in the context of ISTQB terminology?
Question 2
A tester needs to explain Reconnaissance to a non‑technical stakeholder. Which approach is MOST appropriate?
Test your knowledge with real ISTQB-style questions
You’ve learned Reconnaissance. Test your understanding with topic-specific questions in our Mock Exams.