nerdexam
Cisco

350-201 · Question #40

An intruder attempted malicious activity and exchanged emails with a user and received corporate information, including email distribution lists. The intruder asked the user to engage with a link in…

The correct answer is A. social engineering. This question identifies a social engineering attack where an attacker used deception via email to manipulate a user into clicking a malicious link, ultimately compromising the network.

Techniques

Question

An intruder attempted malicious activity and exchanged emails with a user and received corporate information, including email distribution lists. The intruder asked the user to engage with a link in an email. When the fink launched, it infected machines and the intruder was able to access the corporate network. Which testing method did the intruder use?

Options

  • Asocial engineering
  • Beavesdropping
  • Cpiggybacking
  • Dtailgating

How the community answered

(28 responses)
  • A
    93% (26)
  • B
    4% (1)
  • C
    4% (1)

Why each option

This question identifies a social engineering attack where an attacker used deception via email to manipulate a user into clicking a malicious link, ultimately compromising the network.

Asocial engineeringCorrect

Social engineering involves manipulating people through psychological deception rather than technical exploits. The attacker built trust via email communication, extracted sensitive corporate data (distribution lists), and then used that access to deliver a malicious payload - all hallmarks of a phishing-based social engineering campaign targeting human behavior rather than system vulnerabilities.

Beavesdropping

Eavesdropping is a passive interception technique where an attacker silently captures data in transit; it does not involve interacting with or deceiving users.

Cpiggybacking

Piggybacking refers to gaining unauthorized physical access to a secured area by following an authorized person, which is unrelated to email-based deception.

Dtailgating

Tailgating is also a physical access technique where an attacker follows someone through a secured door without using credentials, not an email or network-based attack.

Concept tested: Social engineering attack identification and classification

Source: https://www.cisco.com/c/en/us/products/security/what-is-social-engineering.html

Topics

#social engineering#spear-phishing#attack methodology

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice