nerdexam
(ISC)2

CISSP-ISSAP · Question #174

Which of the following types of attack can be used to break the best physical and logical security mechanism to gain access to a system?

The correct answer is A. Social engineering attack. Social engineering bypasses even the most robust technical defenses by exploiting the weakest link - human psychology - through manipulation, deception, or impersonation to get someone to voluntarily grant access. No firewall or encryption stops an attacker who convinces an…

Infrastructure Security

Question

Which of the following types of attack can be used to break the best physical and logical security mechanism to gain access to a system?

Options

  • ASocial engineering attack
  • BCross site scripting attack
  • CMail bombing
  • DPassword guessing attack

How the community answered

(27 responses)
  • A
    93% (25)
  • B
    4% (1)
  • D
    4% (1)

Explanation

Social engineering bypasses even the most robust technical defenses by exploiting the weakest link - human psychology - through manipulation, deception, or impersonation to get someone to voluntarily grant access. No firewall or encryption stops an attacker who convinces an employee to hand over credentials or hold a door open.

Why the distractors are wrong:

  • B (XSS): A web-based injection attack that targets users through browsers - it requires a technical vulnerability, not a human one, and can't defeat physical security.
  • C (Mail bombing): A denial-of-service tactic that floods a mailbox - it disrupts service but doesn't grant system access.
  • D (Password guessing): Relies on weak passwords and is blocked by lockout policies, MFA, or strong credentials - still a logical/technical attack with logical/technical countermeasures.

Memory tip: Think "best lock, best firewall - still can't stop a liar." Social engineering works around security rather than through it, making it uniquely effective against any level of technical protection.

Topics

#Social engineering#Physical security#Logical security#Access control

Community Discussion

No community discussion yet for this question.

Full CISSP-ISSAP Practice