220-802 · Question #802
An administrator has advised against providing any information over the phone as a way to prevent against which of the following threats?
The correct answer is B. Social engineering. Social engineering attacks manipulate people into divulging confidential information, and vishing (voice-based phishing) over the phone is a classic social engineering technique.
Question
An administrator has advised against providing any information over the phone as a way to prevent against which of the following threats?
Options
- ASession hijacking
- BSocial engineering
- CMan-in-the-middle
- DShoulder surfing
How the community answered
(43 responses)- A7% (3)
- B88% (38)
- C2% (1)
- D2% (1)
Why each option
Social engineering attacks manipulate people into divulging confidential information, and vishing (voice-based phishing) over the phone is a classic social engineering technique.
Session hijacking is a technical attack where an attacker intercepts or steals an authenticated session token to impersonate a user - it does not involve phone calls or information disclosure by the victim.
Social engineering exploits human psychology rather than technical vulnerabilities to obtain sensitive information. Advising employees not to share information over the phone directly counters vishing and pretexting attacks, where an attacker impersonates a trusted party (IT support, bank, etc.) to extract credentials or sensitive data verbally.
Man-in-the-middle attacks intercept network communications between two parties and are a technical network-layer exploit, not a phone-based information disclosure threat.
Shoulder surfing involves physically observing someone's screen or keyboard to steal information - it is a visual eavesdropping technique, not a phone-based threat.
Concept tested: Social engineering threats and phone-based vishing prevention
Source: https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks
Topics
Community Discussion
No community discussion yet for this question.