350-201 · Question #40
An intruder attempted malicious activity and exchanged emails with a user and received corporate information, including email distribution lists. The intruder asked the user to engage with a link in…
The correct answer is A. social engineering. This question identifies a social engineering attack where an attacker used deception via email to manipulate a user into clicking a malicious link, ultimately compromising the network.
Question
An intruder attempted malicious activity and exchanged emails with a user and received corporate information, including email distribution lists. The intruder asked the user to engage with a link in an email. When the fink launched, it infected machines and the intruder was able to access the corporate network. Which testing method did the intruder use?
Options
- Asocial engineering
- Beavesdropping
- Cpiggybacking
- Dtailgating
How the community answered
(28 responses)- A93% (26)
- B4% (1)
- C4% (1)
Why each option
This question identifies a social engineering attack where an attacker used deception via email to manipulate a user into clicking a malicious link, ultimately compromising the network.
Social engineering involves manipulating people through psychological deception rather than technical exploits. The attacker built trust via email communication, extracted sensitive corporate data (distribution lists), and then used that access to deliver a malicious payload - all hallmarks of a phishing-based social engineering campaign targeting human behavior rather than system vulnerabilities.
Eavesdropping is a passive interception technique where an attacker silently captures data in transit; it does not involve interacting with or deceiving users.
Piggybacking refers to gaining unauthorized physical access to a secured area by following an authorized person, which is unrelated to email-based deception.
Tailgating is also a physical access technique where an attacker follows someone through a secured door without using credentials, not an email or network-based attack.
Concept tested: Social engineering attack identification and classification
Source: https://www.cisco.com/c/en/us/products/security/what-is-social-engineering.html
Topics
Community Discussion
No community discussion yet for this question.