nerdexam
CompTIA

220-802 · Question #136

A user receives a phone call from a person claiming to be from technical support. This person knows the user's name and that the user has Windows installed on their computer. The technician directs…

The correct answer is A. Social engineering. Social engineering is the manipulation of people into divulging confidential information or performing actions by exploiting trust, which is exactly what this phone-based impersonation describes.

Networking

Question

A user receives a phone call from a person claiming to be from technical support. This person knows the user's name and that the user has Windows installed on their computer. The technician directs the user to open Event Viewer and look at some event log entries to demonstrate the effects of a virus on the computer. The technician also asks the user for their user ID and password so that they can clean the computer. This is an example of which of the following security threats?

Options

  • ASocial engineering
  • BPhishing
  • CMalware
  • DVirus

How the community answered

(56 responses)
  • A
    88% (49)
  • B
    4% (2)
  • C
    7% (4)
  • D
    2% (1)

Why each option

Social engineering is the manipulation of people into divulging confidential information or performing actions by exploiting trust, which is exactly what this phone-based impersonation describes.

ASocial engineeringCorrect

This scenario is a classic social engineering attack where the attacker uses personal details (the user's name and OS) to establish false credibility, then fabricates a technical pretext (virus in Event Viewer) to create urgency before requesting credentials. Unlike purely technical attacks, social engineering exploits human psychology and trust rather than software vulnerabilities.

BPhishing

Phishing specifically refers to deceptive emails or websites designed to harvest credentials, not phone-based impersonation attacks.

CMalware

Malware is malicious software installed on a system; no software is involved in this phone-based credential theft scenario.

DVirus

A virus is a specific type of self-replicating malicious code; the attacker is fabricating a virus threat as a pretext, not actually deploying one.

Concept tested: Social engineering via impersonation and pretexting

Source: https://learn.microsoft.com/en-us/security/compass/human-operated-ransomware

Topics

#social engineering#security threats#credential theft#impersonation

Community Discussion

No community discussion yet for this question.

Full 220-802 Practice