nerdexam
SAP

C_SEC_2405 · Question #62

A user just received a phone call claiming to be from Tech Support concerning a security vulnerability on the user's computer. The technician requested the user's password to remove a virus. This…

The correct answer is B. Social Engineering. Social engineering (B) is correct because this scenario involves a human manipulating another human through deception - impersonating a trusted authority (Tech Support) to trick the user into surrendering credentials. The attacker exploits trust and urgency rather than any…

Cybersecurity

Question

A user just received a phone call claiming to be from Tech Support concerning a security vulnerability on the user's computer. The technician requested the user's password to remove a virus. This encounter represents which type of cybersecurity attack? Please choose the correct answer.

Options

  • AAdvanced Persistent Threat
  • BSocial Engineering
  • CDenial of Service
  • DMalware Attack

How the community answered

(53 responses)
  • B
    92% (49)
  • C
    6% (3)
  • D
    2% (1)

Explanation

Social engineering (B) is correct because this scenario involves a human manipulating another human through deception - impersonating a trusted authority (Tech Support) to trick the user into surrendering credentials. The attacker exploits trust and urgency rather than any technical vulnerability.

Why the distractors are wrong:

  • A (Advanced Persistent Threat): APTs are long-term, stealthy intrusions by sophisticated attackers (often nation-states) targeting specific organizations - not a quick phone scam.
  • C (Denial of Service): DoS attacks overwhelm systems with traffic to make them unavailable; no human manipulation is involved.
  • D (Malware Attack): Malware requires malicious software to be installed; this attack uses a phone call, not code.

Memory tip: Think "social" = people, not technology. Whenever an attack relies on deceiving or manipulating a person (phishing emails, vishing calls, pretexting), that's social engineering - the exploit is the human, not the machine.

Topics

#social engineering#vishing#attack types#user manipulation

Community Discussion

No community discussion yet for this question.

Full C_SEC_2405 Practice