nerdexam
(ISC)2

CISSP-ISSAP · Question #12

A helpdesk technician received a phone call from an administrator at a remote branch office. The administrator claimed to have forgotten the password for the root account on UNIX servers and asked…

The correct answer is A. Social Engineering attack. Social engineering is the correct answer because the attacker manipulated a human (the technician) into voluntarily disclosing a sensitive credential by exploiting trust, friendliness, and a fabricated scenario - no technical exploit was needed. The technician bypassed security…

Identity and Access Management (IAM) Architecture

Question

A helpdesk technician received a phone call from an administrator at a remote branch office. The administrator claimed to have forgotten the password for the root account on UNIX servers and asked for it. Although the technician didn't know any administrator at the branch office, the guy sounded really friendly and since he knew the root password himself, he supplied the caller with the password. What type of attack has just occurred?

Options

  • ASocial Engineering attack
  • BBrute Force attack
  • CWar dialing attack
  • DReplay attack

How the community answered

(61 responses)
  • A
    80% (49)
  • B
    3% (2)
  • C
    5% (3)
  • D
    11% (7)

Explanation

Social engineering is the correct answer because the attacker manipulated a human (the technician) into voluntarily disclosing a sensitive credential by exploiting trust, friendliness, and a fabricated scenario - no technical exploit was needed. The technician bypassed security protocol (verifying identity) simply because the caller "sounded friendly" and claimed authority, which is the hallmark of social engineering.

  • B (Brute Force) is wrong - brute force involves systematically guessing passwords through automated attempts, not tricking someone into handing one over.
  • C (War Dialing) is wrong - war dialing is scanning phone numbers to find modems or vulnerable systems, a completely different technique.
  • D (Replay Attack) is wrong - a replay attack involves intercepting and retransmitting legitimate network data to impersonate a user; no data was intercepted here.

Memory tip: Think "social" = people. If the attack exploits human psychology (trust, authority, urgency, helpfulness) rather than a technical vulnerability, it's social engineering. The "social" in social engineering always points to the human being the weak link.

Topics

#Social Engineering#Pretexting#Credential Disclosure#Identity Verification

Community Discussion

No community discussion yet for this question.

Full CISSP-ISSAP Practice