GSLC · Question #10
An intruder is trying to get user passwords by pretending to be help desk staff. Which of the following types of security attacks do you think it is?
The correct answer is D. Social Engineering. Impersonating help desk staff to trick users into revealing passwords is a classic social engineering attack using the pretexting technique.
Question
An intruder is trying to get user passwords by pretending to be help desk staff. Which of the following types of security attacks do you think it is?
Options
- AHacking
- BMan-in-the-middle
- CSpoofing
- DSocial Engineering
How the community answered
(38 responses)- A5% (2)
- B3% (1)
- D92% (35)
Why each option
Impersonating help desk staff to trick users into revealing passwords is a classic social engineering attack using the pretexting technique.
Hacking refers to exploiting software, hardware, or network vulnerabilities using technical methods, not psychological manipulation of people.
A man-in-the-middle attack involves technically intercepting and possibly altering communications between two parties at the network level, not impersonating IT staff verbally or over the phone.
Spoofing involves technically forging an identity such as an IP address, email sender, or DNS record at the protocol level, not through direct human-to-human deception.
Social engineering exploits human psychology rather than technical vulnerabilities to gain unauthorized access to information or systems. Impersonating IT or help desk personnel to extract credentials is specifically called pretexting, where the attacker fabricates a plausible scenario to manipulate the victim. No technical exploit is needed - the human is the vulnerability being targeted.
Concept tested: Social engineering pretexting to extract credentials
Source: https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks
Topics
Community Discussion
No community discussion yet for this question.