CISSP-ISSAP · Question #12
A helpdesk technician received a phone call from an administrator at a remote branch office. The administrator claimed to have forgotten the password for the root account on UNIX servers and asked…
The correct answer is A. Social Engineering attack. Social engineering is the correct answer because the attacker manipulated a human (the technician) into voluntarily disclosing a sensitive credential by exploiting trust, friendliness, and a fabricated scenario - no technical exploit was needed. The technician bypassed security…
Question
A helpdesk technician received a phone call from an administrator at a remote branch office. The administrator claimed to have forgotten the password for the root account on UNIX servers and asked for it. Although the technician didn't know any administrator at the branch office, the guy sounded really friendly and since he knew the root password himself, he supplied the caller with the password. What type of attack has just occurred?
Options
- ASocial Engineering attack
- BBrute Force attack
- CWar dialing attack
- DReplay attack
How the community answered
(61 responses)- A80% (49)
- B3% (2)
- C5% (3)
- D11% (7)
Explanation
Social engineering is the correct answer because the attacker manipulated a human (the technician) into voluntarily disclosing a sensitive credential by exploiting trust, friendliness, and a fabricated scenario - no technical exploit was needed. The technician bypassed security protocol (verifying identity) simply because the caller "sounded friendly" and claimed authority, which is the hallmark of social engineering.
- B (Brute Force) is wrong - brute force involves systematically guessing passwords through automated attempts, not tricking someone into handing one over.
- C (War Dialing) is wrong - war dialing is scanning phone numbers to find modems or vulnerable systems, a completely different technique.
- D (Replay Attack) is wrong - a replay attack involves intercepting and retransmitting legitimate network data to impersonate a user; no data was intercepted here.
Memory tip: Think "social" = people. If the attack exploits human psychology (trust, authority, urgency, helpfulness) rather than a technical vulnerability, it's social engineering. The "social" in social engineering always points to the human being the weak link.
Topics
Community Discussion
No community discussion yet for this question.