nerdexam
LPI

303-300 · Question #104

What is social engineering?

The correct answer is D. A type of attack that exploits human psychology to gain access to sensitive information. D is correct because social engineering exploits human psychology - think phishing emails, pretexting, or impersonation - to trick people into revealing passwords, credentials, or sensitive data. The attack vector is the person, not the technology. Why the distractors are…

Access Control

Question

What is social engineering?

Options

  • AA type of virus
  • BA type of malware that disguises itself as legitimate software
  • CA type of denial-of-service attack
  • DA type of attack that exploits human psychology to gain access to sensitive information

How the community answered

(49 responses)
  • A
    8% (4)
  • B
    2% (1)
  • C
    4% (2)
  • D
    86% (42)

Explanation

D is correct because social engineering exploits human psychology - think phishing emails, pretexting, or impersonation - to trick people into revealing passwords, credentials, or sensitive data. The attack vector is the person, not the technology.

Why the distractors are wrong:

  • A (virus): A virus is self-replicating malicious code that infects files - purely technical, no human manipulation involved.
  • B (malware disguised as legitimate software): That describes a Trojan horse, a specific malware category, not a psychological manipulation technique.
  • C (denial-of-service): A DoS attack floods systems to make them unavailable - again, a technical exploit with no human psychology component.

Memory tip: Think of "social" as the key word - social engineering attacks people socially (conversation, deception, trust-building), not systems directly. If an attack requires a human to be fooled, it's social engineering.

Topics

#Social Engineering#Human Psychology#Attack Vector#Access Control Bypass

Community Discussion

No community discussion yet for this question.

Full 303-300 Practice