nerdexam
EC-Council

312-50V11 · Question #96

Within the context of Computer Security, which of the following statements describes Social Engineering best?

The correct answer is C. Social Engineering is the act of getting needed information from a person rather than breaking into. Social engineering is a non-technical attack method that manipulates people into revealing confidential information instead of exploiting system vulnerabilities.

Social Engineering

Question

Within the context of Computer Security, which of the following statements describes Social Engineering best?

Options

  • ASocial Engineering is the act of publicly disclosing information
  • BSocial Engineering is the means put in place by human resource to perform time accounting
  • CSocial Engineering is the act of getting needed information from a person rather than breaking into
  • DSocial Engineering is a training program within sociology studies

How the community answered

(61 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    93% (57)
  • D
    3% (2)

Why each option

Social engineering is a non-technical attack method that manipulates people into revealing confidential information instead of exploiting system vulnerabilities.

ASocial Engineering is the act of publicly disclosing information

Publicly disclosing information describes a data breach or whistleblowing activity, not social engineering, which involves targeted deception of specific individuals to extract information.

BSocial Engineering is the means put in place by human resource to perform time accounting

Time accounting by human resources is an organizational administrative function entirely unrelated to cybersecurity attack techniques or adversarial behavior.

CSocial Engineering is the act of getting needed information from a person rather than breaking intoCorrect

Social engineering in cybersecurity is defined as the psychological manipulation of individuals to obtain confidential information or access, bypassing technical controls entirely. Rather than exploiting software or hardware, an attacker deceives or coerces a person - such as a help desk employee or end user - into providing credentials, access, or sensitive data. The technique relies on human trust and error rather than technical vulnerabilities.

DSocial Engineering is a training program within sociology studies

Social engineering in security has no connection to academic sociology training programs; it refers specifically to human-based attack vectors used by adversaries to manipulate victims.

Concept tested: Social engineering definition in cybersecurity

Source: https://csrc.nist.gov/glossary/term/social_engineering

Topics

#social engineering#human manipulation#information gathering#security awareness

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice