nerdexam
CompTIA

CAS-003 · Question #37

A Chief Information Officer (CIO) publicly announces the implementation of a new financial system. As part of a security assessment that includes a social engineering task, which of the following…

The correct answer is A. Call the CIO and ask for an interview, posing as a job seeker interested in an open position. This is a social engineering assessment task, specifically demonstrating how an attacker can extract sensitive information through pretexting. Option A is the best choice because posing as a job seeker and calling the CIO is a classic, low-risk pretexting scenario that can…

Enterprise Security Operations

Question

A Chief Information Officer (CIO) publicly announces the implementation of a new financial system. As part of a security assessment that includes a social engineering task, which of the following tasks should be conducted to demonstrate the BEST means to gain information to use for a report on social vulnerability details about the financial system?

Options

  • ACall the CIO and ask for an interview, posing as a job seeker interested in an open position
  • BCompromise the email server to obtain a list of attendees who responded to the invitation who is
  • CNotify the CIO that, through observation at events, malicious actors can identify individuals to
  • DUnderstand the CIO is a social drinker, and find the means to befriend the CIO at establishments

How the community answered

(26 responses)
  • A
    77% (20)
  • B
    8% (2)
  • C
    12% (3)
  • D
    4% (1)

Explanation

This is a social engineering assessment task, specifically demonstrating how an attacker can extract sensitive information through pretexting. Option A is the best choice because posing as a job seeker and calling the CIO is a classic, low-risk pretexting scenario that can elicit detailed information about the financial system (team structure, technology stack, vendors, timelines) without requiring any technical attack. It directly demonstrates social vulnerability in a reportable, ethical, and controlled manner. Option B (compromising the email server) is an active technical exploit, not a social engineering demonstration, and is outside scope. Option C is a notification, not an information-gathering action. Option D (befriending the CIO at bars) could work but is impractical, time-consuming, not suitable for a formal assessment, and not easily documentable for a report.

Topics

#social engineering#OSINT#pretexting#security assessment

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice