CAS-003 · Question #660
As part of an organization's ongoing vulnerability assessment program, the Chief Information Security Officer (CISO) wants to evaluate the organization's systems, personnel, and facilities for…
The correct answer is E. Tailgating G. Vishing H. Badge skimming. Social engineering and physical penetration testing specifically target human behavior and physical access controls, not software vulnerabilities. Tailgating (E) involves physically following an authorized person through a secured door without presenting credentials, testing…
Question
As part of an organization's ongoing vulnerability assessment program, the Chief Information Security Officer (CISO) wants to evaluate the organization's systems, personnel, and facilities for various threats. As part of the assessment the CISO plans to engage an independent cybersecurity assessment firm to perform social engineering and physical penetration testing against the organization's corporate offices and remote locations. Which of the following techniques would MOST likely be employed as part of this assessment? (Select THREE).
Options
- APrivilege escalation
- BSQL injection
- CTOC/TOU exploitation
- DRogue AP substitution
- ETailgating
- FVulnerability scanning
- GVishing
- HBadge skimming
How the community answered
(43 responses)- C2% (1)
- D2% (1)
- E91% (39)
- F5% (2)
Explanation
Social engineering and physical penetration testing specifically target human behavior and physical access controls, not software vulnerabilities. Tailgating (E) involves physically following an authorized person through a secured door without presenting credentials, testing whether employees challenge unknown individuals. Vishing (G) is voice-based phishing - calling employees and manipulating them into revealing credentials, access codes, or sensitive information. Badge skimming (H) uses an RFID/NFC reader to covertly copy proximity card data, allowing the tester to clone access badges and bypass physical entry controls. Privilege escalation (A), SQL injection (B), and TOC/TOU exploitation (C) are technical software attacks unrelated to physical/social testing. Rogue AP substitution (D) is a wireless network attack. Vulnerability scanning (F) is an automated technical assessment, not a social or physical technique.
Topics
Community Discussion
No community discussion yet for this question.