nerdexam
Exams220-1002Questions#523
CompTIA

220-1002 · Question #523

220-1002 Question #523: Real Exam Question with Answer & Explanation

The correct answer is B: Strong passwords. Social engineering attacks exploit human psychology rather than technical vulnerabilities, so the security controls it can bypass are those that depend on human behavior. Strong passwords (B) can be defeated through social engineering - an attacker can trick a user into revealing

Question

Which of the following security concepts can be overcome through soc al engineering? (Select TWO)

Options

  • APort blocking
  • BStrong passwords
  • CFirewalls
  • DMAC filtering
  • EEmail attachment filtering
  • FAntivirus updates

Explanation

Social engineering attacks exploit human psychology rather than technical vulnerabilities, so the security controls it can bypass are those that depend on human behavior. Strong passwords (B) can be defeated through social engineering - an attacker can trick a user into revealing their password via phishing, pretexting (impersonating IT support), or vishing (voice phishing), completely bypassing the password's technical strength. Email attachment filtering (E) can be bypassed when an attacker convinces a user to disable filtering, whitelist a malicious sender, or retrieve a malicious file via an alternative method (cloud link, USB, etc.) rather than as a direct attachment. The remaining options - port blocking (A), firewalls (C), MAC filtering (D), and antivirus updates (F) - are purely technical controls implemented at the network or system level that operate independently of user action and cannot be disabled by manipulating a person alone.

Community Discussion

No community discussion yet for this question.

Full 220-1002 Practice