nerdexam
GIAC

GSLC · Question #150

John works as an IT Technician for PassGuide Inc. One morning, John receives an e-mail from the company's Manager asking him to provide his logon ID and password, but the company policy restricts…

The correct answer is A. Social engineering. Receiving an email impersonating a manager to trick an employee into revealing credentials is a classic social engineering attack. The attacker exploits trust rather than a technical vulnerability.

Security Awareness & Training

Question

John works as an IT Technician for PassGuide Inc. One morning, John receives an e-mail from the company's Manager asking him to provide his logon ID and password, but the company policy restricts users from disclosing their logon IDs and passwords. Which type of possible attack is this?

Options

  • ASocial engineering
  • BReplay attack
  • CTrojan horse
  • DDoS

How the community answered

(30 responses)
  • A
    90% (27)
  • B
    3% (1)
  • D
    7% (2)

Why each option

Receiving an email impersonating a manager to trick an employee into revealing credentials is a classic social engineering attack. The attacker exploits trust rather than a technical vulnerability.

ASocial engineeringCorrect

Social engineering involves manipulating individuals into divulging confidential information by impersonating a trusted authority figure - in this case, a manager requesting logon credentials via email, which bypasses technical controls by exploiting human trust.

BReplay attack

A replay attack involves intercepting a valid network transmission (such as an authentication token) and retransmitting it to gain unauthorized access - no human manipulation is involved.

CTrojan horse

A Trojan horse is malicious software disguised as a legitimate program delivered to a victim's system - no deceptive email asking for credentials is involved.

DDoS

A Denial of Service (DoS) attack floods a system or network with traffic to make it unavailable to legitimate users - it does not involve credential theft through impersonation.

Concept tested: Social engineering attack identification via impersonation

Source: https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks

Topics

#social engineering#credential phishing#user security awareness#attack recognition

Community Discussion

No community discussion yet for this question.

Full GSLC Practice