CAS-003 · Question #37
A Chief Information Officer (CIO) publicly announces the implementation of a new financial system. As part of a security assessment that includes a social engineering task, which of the following…
The correct answer is A. Call the CIO and ask for an interview, posing as a job seeker interested in an open position. This is a social engineering assessment task, specifically demonstrating how an attacker can extract sensitive information through pretexting. Option A is the best choice because posing as a job seeker and calling the CIO is a classic, low-risk pretexting scenario that can…
Question
A Chief Information Officer (CIO) publicly announces the implementation of a new financial system. As part of a security assessment that includes a social engineering task, which of the following tasks should be conducted to demonstrate the BEST means to gain information to use for a report on social vulnerability details about the financial system?
Options
- ACall the CIO and ask for an interview, posing as a job seeker interested in an open position
- BCompromise the email server to obtain a list of attendees who responded to the invitation who is
- CNotify the CIO that, through observation at events, malicious actors can identify individuals to
- DUnderstand the CIO is a social drinker, and find the means to befriend the CIO at establishments
How the community answered
(26 responses)- A77% (20)
- B8% (2)
- C12% (3)
- D4% (1)
Explanation
This is a social engineering assessment task, specifically demonstrating how an attacker can extract sensitive information through pretexting. Option A is the best choice because posing as a job seeker and calling the CIO is a classic, low-risk pretexting scenario that can elicit detailed information about the financial system (team structure, technology stack, vendors, timelines) without requiring any technical attack. It directly demonstrates social vulnerability in a reportable, ethical, and controlled manner. Option B (compromising the email server) is an active technical exploit, not a social engineering demonstration, and is outside scope. Option C is a notification, not an information-gathering action. Option D (befriending the CIO at bars) could work but is impractical, time-consuming, not suitable for a formal assessment, and not easily documentable for a report.
Topics
Community Discussion
No community discussion yet for this question.