nerdexam
GIAC

GSLC · Question #174

In which of the following Person-to-Person social engineering attacks does an attacker pretend to be an outside contractor, delivery person, etc., in order to gain physical access to the organization?

The correct answer is D. Impersonation attack. Impersonation attacks involve an attacker assuming a false identity - such as a contractor or delivery person - to deceive personnel and gain unauthorized physical or logical access.

Security Awareness & Training

Question

In which of the following Person-to-Person social engineering attacks does an attacker pretend to be an outside contractor, delivery person, etc., in order to gain physical access to the organization?

Options

  • AIn person attack
  • BThird-party authorization attack
  • CImportant user posing attack
  • DImpersonation attack

How the community answered

(27 responses)
  • A
    7% (2)
  • B
    4% (1)
  • D
    89% (24)

Why each option

Impersonation attacks involve an attacker assuming a false identity - such as a contractor or delivery person - to deceive personnel and gain unauthorized physical or logical access.

AIn person attack

In-person attack is an overly broad category descriptor, not a specific named social engineering technique.

BThird-party authorization attack

Third-party authorization attack involves falsely claiming someone else has already approved an action, not assuming a physical identity.

CImportant user posing attack

Important user posing involves pretending to be a senior executive or high-privilege user to pressure staff, not an outside contractor.

DImpersonation attackCorrect

Impersonation is the social engineering technique where an attacker adopts a believable false persona (contractor, vendor, delivery courier) to manipulate people into granting access. It is classified as a Person-to-Person attack because it relies on direct human interaction and deception rather than technical exploitation. The physical access dimension described in the question is a hallmark of impersonation attacks.

Concept tested: Social engineering impersonation attack classification

Source: https://www.comptia.org/blog/what-is-social-engineering

Topics

#social engineering#impersonation#physical access#person-to-person attack

Community Discussion

No community discussion yet for this question.

Full GSLC Practice