nerdexam
CompTIA

CAS-003 · Question #27

A penetration tester has been contracted to conduct a physical assessment of a site. Which of the following is the MOST plausible method of social engineering to be conducted during this engagement?

The correct answer is A. Randomly calling customer employees and posing as a help desk technician requiring user. During a physical penetration test, a tester often needs an initial foothold or credential to proceed. Option A - calling employees while posing as a help desk technician requesting user credentials - is considered plausible because help desk impersonation is one of the most…

Enterprise Security Operations

Question

A penetration tester has been contracted to conduct a physical assessment of a site. Which of the following is the MOST plausible method of social engineering to be conducted during this engagement?

Options

  • ARandomly calling customer employees and posing as a help desk technician requiring user
  • BPosing as a copier service technician and indicating the equipment had "phoned home" to alert
  • CSimulating an illness while at a client location for a sales call and then recovering once listening
  • DObtaining fake government credentials and impersonating law enforcement to gain access to a

How the community answered

(49 responses)
  • A
    80% (39)
  • B
    2% (1)
  • C
    12% (6)
  • D
    6% (3)

Explanation

During a physical penetration test, a tester often needs an initial foothold or credential to proceed. Option A - calling employees while posing as a help desk technician requesting user credentials - is considered plausible because help desk impersonation is one of the most historically successful social engineering vectors. Employees are often conditioned to comply with IT authority figures, especially over the phone. This technique can yield credentials that support the physical assessment. Option B (posing as a copier technician) is also a classic physical technique, but the specific scenario described - claiming the device 'phoned home' - is a more elaborate and potentially suspicious pretext. Option C (simulating illness) is theatrical, implausible as a repeatable pen test technique, and ethically problematic. Option D (impersonating law enforcement with fake credentials) is illegal and outside the bounds of any legitimate engagement.

Topics

#social engineering#physical penetration testing#pretexting#impersonation

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice