nerdexam
EC-Council

212-82 · Question #38

Johnson, an attacker, performed online research for the contact details of reputed cybersecurity firms. He found the contact number of sibertech.org and dialed the number, claiming himself to represen

The correct answer is A. Quid pro quo. Explanation Option A (Quid pro quo) is correct because this attack involves an exchange where Johnson offers a service (technical support/warning about a server compromise) in return for the victim giving something of value (executing commands and installing malicious files that

Submitted by haru.x· Mar 6, 2026Cloud Security Risks & Threat Mitigation

Question

Johnson, an attacker, performed online research for the contact details of reputed cybersecurity firms. He found the contact number of sibertech.org and dialed the number, claiming himself to represent a technical support team from a vendor. He warned that a specific server is about to be compromised and requested sibertech.org to follow the provided instructions. Consequently, he prompted the victim to execute unusual commands and install malicious files, which were then used to collect and pass critical Information to Johnson's machine. What is the social engineering technique Steve employed in the above scenario?

Options

  • AQuid pro quo
  • BDiversion theft
  • CElicitation
  • DPhishing

How the community answered

(30 responses)
  • A
    87% (26)
  • B
    3% (1)
  • C
    3% (1)
  • D
    7% (2)

Explanation

Explanation

Option A (Quid pro quo) is correct because this attack involves an exchange where Johnson offers a service (technical support/warning about a server compromise) in return for the victim giving something of value (executing commands and installing malicious files that surrender critical information) - a classic "something for something" trade under false pretenses.

Why the distractors are wrong:

  • B (Diversion theft) involves redirecting a delivery or transaction to a different location, which is not what occurred here
  • C (Elicitation) involves subtly extracting information through casual conversation without the target realizing it; Johnson's approach was more directive and action-based
  • D (Phishing) is conducted via fraudulent emails or websites, not phone calls (phone-based attacks are specifically called "vishing")

Memory Tip: Think of quid pro quo as the "IT help desk scam" - the attacker poses as tech support offering help in exchange for access or compliance. If someone calls you unsolicited offering to "fix" something in exchange for your cooperation, that's the quid pro quo red flag. The Latin phrase itself means "something for something," which perfectly describes this exchange.

Topics

#Social Engineering#Quid pro quo#Pretexting

Community Discussion

No community discussion yet for this question.

Full 212-82 Practice