220-802 · Question #351
A user receives an unsolicited call from a technician claiming to be from a Microsoft certified partner. The technician tricks the user into allowing them access to their PC because of malware…
The correct answer is C. Social engineering. This scenario describes a phone-based manipulation tactic where an attacker impersonates a trusted vendor to gain remote PC access. This is a classic social engineering attack that exploits human trust rather than technical vulnerabilities.
Question
A user receives an unsolicited call from a technician claiming to be from a Microsoft certified partner. The technician tricks the user into allowing them access to their PC because of malware alerts that were being broadcasted. Which of the following attacks is this user a victim of?
Options
- AShoulder surfing
- BPhishing attack
- CSocial engineering
- DMalware infection
How the community answered
(40 responses)- A3% (1)
- C95% (38)
- D3% (1)
Why each option
This scenario describes a phone-based manipulation tactic where an attacker impersonates a trusted vendor to gain remote PC access. This is a classic social engineering attack that exploits human trust rather than technical vulnerabilities.
Shoulder surfing involves physically observing someone's screen or keyboard to steal information and requires the attacker to be physically present.
Phishing is a deceptive attack delivered via email or malicious links, not through an unsolicited voice call from an impersonator.
Social engineering is the practice of psychologically manipulating people into performing actions or divulging information by impersonating a trusted authority - in this case, a fake Microsoft partner technician. The attacker crafted a convincing false pretense (malware alerts) to gain the user's trust and consent for remote access. No technical exploit was used; the attack succeeded entirely through human deception.
A malware infection refers to malicious software being installed on a system; while remote access tools may be used after the social engineering succeeds, the attack vector itself is human manipulation.
Concept tested: Social engineering via impersonation and pretexting
Source: https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks
Topics
Community Discussion
No community discussion yet for this question.