GSLC · Question #150
John works as an IT Technician for PassGuide Inc. One morning, John receives an e-mail from the company's Manager asking him to provide his logon ID and password, but the company policy restricts…
The correct answer is A. Social engineering. Receiving an email impersonating a manager to trick an employee into revealing credentials is a classic social engineering attack. The attacker exploits trust rather than a technical vulnerability.
Question
John works as an IT Technician for PassGuide Inc. One morning, John receives an e-mail from the company's Manager asking him to provide his logon ID and password, but the company policy restricts users from disclosing their logon IDs and passwords. Which type of possible attack is this?
Options
- ASocial engineering
- BReplay attack
- CTrojan horse
- DDoS
How the community answered
(30 responses)- A90% (27)
- B3% (1)
- D7% (2)
Why each option
Receiving an email impersonating a manager to trick an employee into revealing credentials is a classic social engineering attack. The attacker exploits trust rather than a technical vulnerability.
Social engineering involves manipulating individuals into divulging confidential information by impersonating a trusted authority figure - in this case, a manager requesting logon credentials via email, which bypasses technical controls by exploiting human trust.
A replay attack involves intercepting a valid network transmission (such as an authentication token) and retransmitting it to gain unauthorized access - no human manipulation is involved.
A Trojan horse is malicious software disguised as a legitimate program delivered to a victim's system - no deceptive email asking for credentials is involved.
A Denial of Service (DoS) attack floods a system or network with traffic to make it unavailable to legitimate users - it does not involve credential theft through impersonation.
Concept tested: Social engineering attack identification via impersonation
Source: https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks
Topics
Community Discussion
No community discussion yet for this question.