nerdexam
EC-Council

112-52 · Question #133

What technique involves the social engineer pretending to be someone else to obtain sensitive information?

The correct answer is C. Pretexting. Pretexting is the technique where an attacker fabricates a convincing scenario (a "pretext") and assumes a false identity to manipulate a target into revealing sensitive information - for example, impersonating IT support to extract a password. Phishing (A) is wrong because it…

Attacks and Countermeasures

Question

What technique involves the social engineer pretending to be someone else to obtain sensitive information?

Options

  • APhishing
  • BBaiting
  • CPretexting
  • DTailgating

How the community answered

(38 responses)
  • A
    8% (3)
  • B
    3% (1)
  • C
    87% (33)
  • D
    3% (1)

Explanation

Pretexting is the technique where an attacker fabricates a convincing scenario (a "pretext") and assumes a false identity to manipulate a target into revealing sensitive information - for example, impersonating IT support to extract a password. Phishing (A) is wrong because it uses deceptive emails or links to trick victims, not identity impersonation directly. Baiting (B) relies on luring victims with something enticing (like a free USB drive), not a false persona. Tailgating (D) is a physical security attack - following someone through a secured door - with no information-gathering component.

Memory tip: Think of pretext as "pre-text" - the attacker writes a script (a fabricated story) before the attack, then plays a character to deliver it.

Topics

#Social Engineering#Pretexting#Information Gathering#Attack Techniques

Community Discussion

No community discussion yet for this question.

Full 112-52 Practice