nerdexam
CompTIA

CAS-001 · Question #16

A security administrator has been conducting a security assessment of Company XYZ for the past two weeks. All of the penetration tests and other assessments have revealed zero flaws in the systems…

The correct answer is C. Social engineering. When all technical assessments (penetration testing, vulnerability scanning) return clean results yet significant data breaches are still occurring, the most likely attack vector is the human element-social engineering. Attackers may be manipulating employees through phishing…

Research and Analysis

Question

A security administrator has been conducting a security assessment of Company XYZ for the past two weeks. All of the penetration tests and other assessments have revealed zero flaws in the systems at Company XYZ. However, Company XYZ reports that it has been the victim of numerous security incidents in the past six months. In each of these incidents, the criminals have managed to exfiltrate large volumes of data from the secure servers at the company. Which of the following techniques should the investigation team consider in the next phase of their assessment in hopes of uncovering the attack vector the criminals used?

Options

  • AVulnerability assessment
  • BCode review
  • CSocial engineering
  • DReverse engineering

How the community answered

(65 responses)
  • A
    9% (6)
  • B
    18% (12)
  • C
    68% (44)
  • D
    5% (3)

Explanation

When all technical assessments (penetration testing, vulnerability scanning) return clean results yet significant data breaches are still occurring, the most likely attack vector is the human element-social engineering. Attackers may be manipulating employees through phishing, pretexting, vishing, or in-person deception to gain credentials or physical access to systems without triggering any technical control. Option A (vulnerability assessment) is redundant since extensive technical testing already found zero flaws. Option B (code review) could uncover application vulnerabilities but would not explain already-occurring exfiltration through non-technical means. Option D (reverse engineering) is used to analyze malware or hardware and is not appropriate as an investigative next step in this context. Social engineering is often the weakest link when technical defenses are strong.

Topics

#social engineering#data exfiltration#penetration testing#security assessment

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice