nerdexam
CIW

1D0-61B · Question #6

Which of the following is the common name for the practice hackers use to trick people into revealing sensitive information?

The correct answer is A. Social engineering. Social engineering (A) is the well-established term for manipulating people psychologically to divulge confidential information or perform actions that compromise security - it's the recognized term used across cybersecurity certifications (CompTIA, CISSP, CEH) and industry…

Web Site Development and Management

Question

Which of the following is the common name for the practice hackers use to trick people into revealing sensitive information?

Options

  • ASocial engineering
  • BIdentity exploitation
  • CInformation probing
  • DIntellectual deception

How the community answered

(24 responses)
  • A
    92% (22)
  • B
    4% (1)
  • D
    4% (1)

Explanation

Social engineering (A) is the well-established term for manipulating people psychologically to divulge confidential information or perform actions that compromise security - it's the recognized term used across cybersecurity certifications (CompTIA, CISSP, CEH) and industry standards.

The distractors are fabricated terms: Identity exploitation (B) sounds plausible but refers to no standard practice - it conflates social engineering with identity theft. Information probing (C) might suggest network reconnaissance or enumeration, not human manipulation. Intellectual deception (D) is not a recognized security term at all.

Memory tip: Think "social" = people. Social engineering attacks the human layer of security, not the technical one - it's hacking people, not systems. If you remember that, you'll always pick the answer involving human manipulation.

Topics

#social engineering#information security#security awareness#cybersecurity

Community Discussion

4
Lena V.Lena V.Oct 22, 2025

Social engineering is the answer, A. That is the established term the exam uses for manipulation tactics that psychologically trick users into handing over credentials, access, or sensitive data, and it covers everything from phishing calls to pretexting scenarios.

10
Samuel O.Samuel O.Oct 24, 2025

Lena is right on the term, and I will add that when you see a scenario question describing someone calling the help desk and pretending to be an executive to reset a password, the exam still wants "social engineering" as the category answer even though "impersonation" or "vishing" might also appear as options and feel more specific.

0
Naledi M.Naledi M.Nov 15, 2025

"Social engineering" is the industry term, not just the common name, but A is the only defensible pick.

4
Samuel O.Samuel O.Nov 3, 2025

Honestly my first instinct was D, intellectual deception, because when you think about what a hacker is actually doing, they are manipulating someone's thinking, so that framing seemed close. But that term does not exist in any real security framework or certification body's official vocabulary, and that was the tell. B and C have the same problem, they sound plausible in plain English but neither is a defined term you will encounter in CIW, CompTIA, or any other vendor's documentation. Social engineering is the answer because it is the established industry term covering all the techniques where an attacker exploits human psychology rather than a technical vulnerability, phishing, pretexting, vishing, tailgating, all of it falls under that umbrella. Burn that term into your memory because it shows up constantly across multiple cert tracks, not just 1D0-61B.

1
Full 1D0-61B Practice