312-50V11 · Question #939
Ralph, a professional hacker, targeted Jane, who had recently bought new systems for her company. After a few days, Ralph contacted Jane while masquerading as a legitimate customer support…
The correct answer is D. impersonation. Ralph's primary attack technique is impersonation, a social engineering method where an attacker masquerades as a trusted or legitimate individual to gain physical or logical access to a target.
Question
Ralph, a professional hacker, targeted Jane, who had recently bought new systems for her company. After a few days, Ralph contacted Jane while masquerading as a legitimate customer support executive, informing that her systems need to be serviced for proper functioning and that customer support will send a computer technician. Jane promptly replied positively. Ralph entered Jane's company using this opportunity and gathered sensitive information by scanning terminals for passwords, searching for important documents in desks, and rummaging bins. What is the type of attack technique Ralph used on jane?
Options
- ADumpster diving
- BEavesdropping
- CShoulder surfing
- Dimpersonation
How the community answered
(29 responses)- A3% (1)
- B3% (1)
- C7% (2)
- D86% (25)
Why each option
Ralph's primary attack technique is impersonation, a social engineering method where an attacker masquerades as a trusted or legitimate individual to gain physical or logical access to a target.
Dumpster diving refers specifically to searching through discarded materials (trash/bins) for sensitive information; while Ralph did this inside the company, it was only one sub-activity made possible by impersonation, not the primary technique.
Eavesdropping involves passively intercepting communications (network traffic or conversations) without the target's knowledge, which is not described in this scenario.
Shoulder surfing involves directly observing a person's screen or keyboard to obtain credentials or sensitive data, and while Ralph scanned terminals, the overarching technique that enabled all access was impersonation.
Impersonation is a social engineering attack where the attacker pretends to be a legitimate authority or trusted person - in this case Ralph posed as a customer support executive to convince Jane to grant physical access. This deception enabled all subsequent activities (physical entry, password searching, dumpster diving), making impersonation the overarching attack technique used to initiate the breach.
Concept tested: Social engineering impersonation attack technique
Source: https://csrc.nist.gov/glossary/term/impersonation
Topics
Community Discussion
No community discussion yet for this question.