nerdexam
EC-Council

312-50V11 · Question #507

Which of the following is a form of penetration testing that relies heavily on human interaction and often involves tricking people into breaking normal security procedures?

The correct answer is A. Social Engineering. Social engineering is the only answer that describes a broad, people-centric attack methodology relying on psychological manipulation to bypass security procedures.

Social Engineering

Question

Which of the following is a form of penetration testing that relies heavily on human interaction and often involves tricking people into breaking normal security procedures?

Options

  • ASocial Engineering
  • BPiggybacking
  • CTailgating
  • DEavesdropping

How the community answered

(24 responses)
  • A
    92% (22)
  • B
    4% (1)
  • D
    4% (1)

Why each option

Social engineering is the only answer that describes a broad, people-centric attack methodology relying on psychological manipulation to bypass security procedures.

ASocial EngineeringCorrect

Social engineering is the practice of manipulating individuals through deception and psychological tactics to bypass security controls without technical exploitation. It encompasses techniques including phishing, pretexting, and impersonation that all rely on exploiting human trust and behavior. The defining characteristic is that the attacker targets human psychology rather than technical vulnerabilities.

BPiggybacking

Piggybacking is a specific physical access technique where an unauthorized person gains entry by being knowingly allowed through by an authorized person, not a broad manipulation methodology.

CTailgating

Tailgating is a specific physical intrusion method where an attacker follows closely behind an authorized person through a secured entry without their consent.

DEavesdropping

Eavesdropping is a passive interception attack targeting communications or conversations, not a technique that tricks people into breaking security procedures.

Concept tested: Social engineering as a people-centric attack technique

Source: https://csrc.nist.gov/glossary/term/social_engineering

Topics

#social engineering#human interaction#penetration testing#security awareness

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice