nerdexam
CompTIA

220-802 · Question #93

Which of the following security threats does NOT use software to extract sensitive information or credentials?

The correct answer is B. Shoulder surfing. Shoulder surfing is a physical observation technique where an attacker visually watches a target enter credentials or sensitive data, requiring no software tools.

Hardware

Question

Which of the following security threats does NOT use software to extract sensitive information or credentials?

Options

  • AGrayware
  • BShoulder surfing
  • CMalware
  • DMan-in-the-Middle exploits

How the community answered

(20 responses)
  • B
    95% (19)
  • C
    5% (1)

Why each option

Shoulder surfing is a physical observation technique where an attacker visually watches a target enter credentials or sensitive data, requiring no software tools.

AGrayware

Grayware is a category of unwanted software (adware, spyware, tracking tools) that uses code to extract or transmit user data.

BShoulder surfingCorrect

Shoulder surfing relies entirely on a human physically looking over another person's shoulder to observe passwords, PINs, or other sensitive input. Unlike all other listed threats, it requires no malicious software, network access, or code execution - it is a purely social engineering and physical security threat.

CMalware

Malware is by definition malicious software designed to steal credentials or sensitive information from a system.

DMan-in-the-Middle exploits

Man-in-the-Middle exploits use software or network tools to intercept and read communications between two parties.

Concept tested: Physical vs software-based security threats

Source: https://www.comptia.org/blog/security-awareness-shoulder-surfing

Topics

#shoulder surfing#social engineering#physical security#non-software threats

Community Discussion

No community discussion yet for this question.

Full 220-802 Practice