nerdexam
CompTIA

220-802 · Question #831

An administrative assistant receives a phone call from the IT department asking for personal information to update their records. One of the questions asked is the password to the company's…

The correct answer is D. Social engineering. Calling a user and impersonating IT staff to extract sensitive credentials such as passwords is a classic social engineering attack that exploits human trust rather than technical vulnerabilities.

Networking

Question

An administrative assistant receives a phone call from the IT department asking for personal information to update their records. One of the questions asked is the password to the company's administrative portal. Which of the following is occurring?

Options

  • AShoulder surfing
  • BConfiguration management
  • CHelpdesk troubleshooting methodology
  • DSocial engineering

How the community answered

(46 responses)
  • A
    7% (3)
  • B
    2% (1)
  • C
    2% (1)
  • D
    89% (41)

Why each option

Calling a user and impersonating IT staff to extract sensitive credentials such as passwords is a classic social engineering attack that exploits human trust rather than technical vulnerabilities.

AShoulder surfing

Shoulder surfing involves physically observing someone's screen or keyboard to steal credentials and requires the attacker to be physically present.

BConfiguration management

Configuration management is an IT process for tracking and controlling changes to systems and software, not a security attack.

CHelpdesk troubleshooting methodology

Helpdesk troubleshooting methodology refers to the structured process IT staff use to diagnose and resolve technical issues, which is a legitimate practice.

DSocial engineeringCorrect

Social engineering manipulates people into voluntarily disclosing confidential information or performing actions that compromise security, by impersonating a trusted authority such as IT support. This specific technique - using phone calls to extract credentials - is a form of vishing (voice phishing). No legitimate IT department will ever ask for a user's password, making this a clear indicator of a social engineering attack.

Concept tested: Social engineering via phone vishing to steal credentials

Source: https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks

Topics

#social engineering#password theft#phishing#security threats

Community Discussion

No community discussion yet for this question.

Full 220-802 Practice