nerdexam
CompTIA

FC0-U61 · Question #361

Which of the following are types of social engineering attacks? Each correct Answer represents a complete solution. Choose two.

The correct answer is A. An unauthorized person gains entrance to the building where the company's database server C. An unauthorized person calls a user and pretends to be a system administrator in order to get the. Social engineering attacks involve manipulating individuals to perform actions or divulge confidential information, often through psychological manipulation, such as physical unauthorized access or impersonation.

Security

Question

Which of the following are types of social engineering attacks? Each correct Answer represents a complete solution. Choose two.

Options

  • AAn unauthorized person gains entrance to the building where the company's database server
  • BAn unauthorized person inserts an intermediary software or program between two communicating
  • CAn unauthorized person calls a user and pretends to be a system administrator in order to get the
  • DAn unauthorized person modifies packet headers by using someone else's IP address to his

How the community answered

(25 responses)
  • A
    88% (22)
  • B
    8% (2)
  • D
    4% (1)

Why each option

Social engineering attacks involve manipulating individuals to perform actions or divulge confidential information, often through psychological manipulation, such as physical unauthorized access or impersonation.

AAn unauthorized person gains entrance to the building where the company's database serverCorrect

Gaining unauthorized physical entrance to a building, often through methods like tailgating or impersonation, is a classic form of social engineering as it exploits human trust or negligence to bypass physical security.

BAn unauthorized person inserts an intermediary software or program between two communicating

Inserting intermediary software or programs describes a Man-in-the-Middle attack, which is a technical attack, not a social engineering one.

CAn unauthorized person calls a user and pretends to be a system administrator in order to get theCorrect

Pretending to be a system administrator over the phone to trick a user into revealing sensitive information, like login credentials, is a clear example of vishing, a type of social engineering attack. It exploits trust and authority.

DAn unauthorized person modifies packet headers by using someone else's IP address to his

Modifying packet headers with someone else's IP address describes IP spoofing, which is a technical network attack, not social engineering.

Concept tested: Social engineering attack types

Source: https://learn.microsoft.com/en-us/compliance/regulatory/auditing-social-engineering-attacks

Topics

#social engineering#physical security#phishing

Community Discussion

No community discussion yet for this question.

Full FC0-U61 Practice