nerdexam
CompTIA

CAS-003 · Question #660

As part of an organization's ongoing vulnerability assessment program, the Chief Information Security Officer (CISO) wants to evaluate the organization's systems, personnel, and facilities for…

The correct answer is E. Tailgating G. Vishing H. Badge skimming. Social engineering and physical penetration testing specifically target human behavior and physical access controls, not software vulnerabilities. Tailgating (E) involves physically following an authorized person through a secured door without presenting credentials, testing…

Enterprise Security Operations

Question

As part of an organization's ongoing vulnerability assessment program, the Chief Information Security Officer (CISO) wants to evaluate the organization's systems, personnel, and facilities for various threats. As part of the assessment the CISO plans to engage an independent cybersecurity assessment firm to perform social engineering and physical penetration testing against the organization's corporate offices and remote locations. Which of the following techniques would MOST likely be employed as part of this assessment? (Select THREE).

Options

  • APrivilege escalation
  • BSQL injection
  • CTOC/TOU exploitation
  • DRogue AP substitution
  • ETailgating
  • FVulnerability scanning
  • GVishing
  • HBadge skimming

How the community answered

(43 responses)
  • C
    2% (1)
  • D
    2% (1)
  • E
    91% (39)
  • F
    5% (2)

Explanation

Social engineering and physical penetration testing specifically target human behavior and physical access controls, not software vulnerabilities. Tailgating (E) involves physically following an authorized person through a secured door without presenting credentials, testing whether employees challenge unknown individuals. Vishing (G) is voice-based phishing - calling employees and manipulating them into revealing credentials, access codes, or sensitive information. Badge skimming (H) uses an RFID/NFC reader to covertly copy proximity card data, allowing the tester to clone access badges and bypass physical entry controls. Privilege escalation (A), SQL injection (B), and TOC/TOU exploitation (C) are technical software attacks unrelated to physical/social testing. Rogue AP substitution (D) is a wireless network attack. Vulnerability scanning (F) is an automated technical assessment, not a social or physical technique.

Topics

#social engineering#physical penetration testing#tailgating#vishing

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice