nerdexam
EC-Council

312-50V11 · Question #939

Ralph, a professional hacker, targeted Jane, who had recently bought new systems for her company. After a few days, Ralph contacted Jane while masquerading as a legitimate customer support…

The correct answer is D. impersonation. Ralph's primary attack technique is impersonation, a social engineering method where an attacker masquerades as a trusted or legitimate individual to gain physical or logical access to a target.

Social Engineering

Question

Ralph, a professional hacker, targeted Jane, who had recently bought new systems for her company. After a few days, Ralph contacted Jane while masquerading as a legitimate customer support executive, informing that her systems need to be serviced for proper functioning and that customer support will send a computer technician. Jane promptly replied positively. Ralph entered Jane's company using this opportunity and gathered sensitive information by scanning terminals for passwords, searching for important documents in desks, and rummaging bins. What is the type of attack technique Ralph used on jane?

Options

  • ADumpster diving
  • BEavesdropping
  • CShoulder surfing
  • Dimpersonation

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    7% (2)
  • D
    86% (25)

Why each option

Ralph's primary attack technique is impersonation, a social engineering method where an attacker masquerades as a trusted or legitimate individual to gain physical or logical access to a target.

ADumpster diving

Dumpster diving refers specifically to searching through discarded materials (trash/bins) for sensitive information; while Ralph did this inside the company, it was only one sub-activity made possible by impersonation, not the primary technique.

BEavesdropping

Eavesdropping involves passively intercepting communications (network traffic or conversations) without the target's knowledge, which is not described in this scenario.

CShoulder surfing

Shoulder surfing involves directly observing a person's screen or keyboard to obtain credentials or sensitive data, and while Ralph scanned terminals, the overarching technique that enabled all access was impersonation.

DimpersonationCorrect

Impersonation is a social engineering attack where the attacker pretends to be a legitimate authority or trusted person - in this case Ralph posed as a customer support executive to convince Jane to grant physical access. This deception enabled all subsequent activities (physical entry, password searching, dumpster diving), making impersonation the overarching attack technique used to initiate the breach.

Concept tested: Social engineering impersonation attack technique

Source: https://csrc.nist.gov/glossary/term/impersonation

Topics

#impersonation#social engineering#pretexting#physical access

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice