nerdexam
EC-Council

312-50V12 · Question #82

Johnson, an attacker, performed online research for the contact details of reputed cybersecurity firms. He found the contact number of sibertech.org and dialed the number, claiming himself to…

The correct answer is C. Elicitation. Explanation Elicitation (Option C) is correct because Johnson used deceptive conversation and manipulation - posing as a trusted vendor's technical support - to extract actions and information from the victim without raising suspicion. Elicitation is a social engineering…

Submitted by akirajp· Mar 4, 2026System Hacking Phases and Attack Techniques

Question

Johnson, an attacker, performed online research for the contact details of reputed cybersecurity firms. He found the contact number of sibertech.org and dialed the number, claiming himself to represent a technical support team from a vendor. He warned that a specific server is about to be compromised and requested sibertech.org to follow the provided instructions. Consequently, he prompted the victim to execute unusual commands and install malicious files, which were then used to collect and pass critical information to Johnson's machine. What is the social engineering technique Steve employed in the above scenario?

Options

  • ADiversion theft
  • BQuid pro quo
  • CElicitation
  • DPhishing

How the community answered

(44 responses)
  • A
    16% (7)
  • B
    9% (4)
  • C
    73% (32)
  • D
    2% (1)

Explanation

Explanation

Elicitation (Option C) is correct because Johnson used deceptive conversation and manipulation - posing as a trusted vendor's technical support - to extract actions and information from the victim without raising suspicion. Elicitation is a social engineering technique where an attacker skillfully draws out information or behavior from a target through seemingly legitimate interaction, which is exactly what Johnson did by prompting the victim to execute commands and install malicious files.

Why the distractors are wrong:

  • Diversion Theft (A) involves redirecting a delivery or transaction to a different location - it's physically oriented and doesn't apply here.
  • Quid Pro Quo (B) involves offering something in exchange for information (e.g., "I'll fix your computer if you give me your credentials") - Johnson made no such exchange offer.
  • Phishing (D) is conducted via fraudulent emails or websites, not phone calls; a phone-based attack would more specifically be called vishing (voice phishing).

Memory Tip: Think of elicitation as "drawing out" - the attacker elicits actions or information through clever, trust-based conversation. If the attack involves talking someone into doing something without a direct exchange or email link, think elicitation.

Topics

#Social Engineering#Elicitation#Vishing#Malware

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice