nerdexam
CompTIA

220-802 · Question #351

A user receives an unsolicited call from a technician claiming to be from a Microsoft certified partner. The technician tricks the user into allowing them access to their PC because of malware…

The correct answer is C. Social engineering. This scenario describes a phone-based manipulation tactic where an attacker impersonates a trusted vendor to gain remote PC access. This is a classic social engineering attack that exploits human trust rather than technical vulnerabilities.

Networking

Question

A user receives an unsolicited call from a technician claiming to be from a Microsoft certified partner. The technician tricks the user into allowing them access to their PC because of malware alerts that were being broadcasted. Which of the following attacks is this user a victim of?

Options

  • AShoulder surfing
  • BPhishing attack
  • CSocial engineering
  • DMalware infection

How the community answered

(40 responses)
  • A
    3% (1)
  • C
    95% (38)
  • D
    3% (1)

Why each option

This scenario describes a phone-based manipulation tactic where an attacker impersonates a trusted vendor to gain remote PC access. This is a classic social engineering attack that exploits human trust rather than technical vulnerabilities.

AShoulder surfing

Shoulder surfing involves physically observing someone's screen or keyboard to steal information and requires the attacker to be physically present.

BPhishing attack

Phishing is a deceptive attack delivered via email or malicious links, not through an unsolicited voice call from an impersonator.

CSocial engineeringCorrect

Social engineering is the practice of psychologically manipulating people into performing actions or divulging information by impersonating a trusted authority - in this case, a fake Microsoft partner technician. The attacker crafted a convincing false pretense (malware alerts) to gain the user's trust and consent for remote access. No technical exploit was used; the attack succeeded entirely through human deception.

DMalware infection

A malware infection refers to malicious software being installed on a system; while remote access tools may be used after the social engineering succeeds, the attack vector itself is human manipulation.

Concept tested: Social engineering via impersonation and pretexting

Source: https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks

Topics

#social engineering#user awareness#phishing#security attack

Community Discussion

No community discussion yet for this question.

Full 220-802 Practice