1D0-61B · Question #6
Which of the following is the common name for the practice hackers use to trick people into revealing sensitive information?
The correct answer is A. Social engineering. Social engineering (A) is the well-established term for manipulating people psychologically to divulge confidential information or perform actions that compromise security - it's the recognized term used across cybersecurity certifications (CompTIA, CISSP, CEH) and industry…
Question
Which of the following is the common name for the practice hackers use to trick people into revealing sensitive information?
Options
- ASocial engineering
- BIdentity exploitation
- CInformation probing
- DIntellectual deception
How the community answered
(24 responses)- A92% (22)
- B4% (1)
- D4% (1)
Explanation
Social engineering (A) is the well-established term for manipulating people psychologically to divulge confidential information or perform actions that compromise security - it's the recognized term used across cybersecurity certifications (CompTIA, CISSP, CEH) and industry standards.
The distractors are fabricated terms: Identity exploitation (B) sounds plausible but refers to no standard practice - it conflates social engineering with identity theft. Information probing (C) might suggest network reconnaissance or enumeration, not human manipulation. Intellectual deception (D) is not a recognized security term at all.
Memory tip: Think "social" = people. Social engineering attacks the human layer of security, not the technical one - it's hacking people, not systems. If you remember that, you'll always pick the answer involving human manipulation.
Topics
Community Discussion
4Social engineering is the answer, A. That is the established term the exam uses for manipulation tactics that psychologically trick users into handing over credentials, access, or sensitive data, and it covers everything from phishing calls to pretexting scenarios.
Lena is right on the term, and I will add that when you see a scenario question describing someone calling the help desk and pretending to be an executive to reset a password, the exam still wants "social engineering" as the category answer even though "impersonation" or "vishing" might also appear as options and feel more specific.
"Social engineering" is the industry term, not just the common name, but A is the only defensible pick.
Honestly my first instinct was D, intellectual deception, because when you think about what a hacker is actually doing, they are manipulating someone's thinking, so that framing seemed close. But that term does not exist in any real security framework or certification body's official vocabulary, and that was the tell. B and C have the same problem, they sound plausible in plain English but neither is a defined term you will encounter in CIW, CompTIA, or any other vendor's documentation. Social engineering is the answer because it is the established industry term covering all the techniques where an attacker exploits human psychology rather than a technical vulnerability, phishing, pretexting, vishing, tailgating, all of it falls under that umbrella. Burn that term into your memory because it shows up constantly across multiple cert tracks, not just 1D0-61B.