nerdexam
GIAC

GSLC · Question #178

You work as a technician for Secure Net Inc. You receive an e-mail from your software vendor. The e-mail contains information about a critical fix that needs to be installed on your computer. It…

The correct answer is A. Social engineering. This scenario describes social engineering - an attacker uses urgency, fear, and impersonation to manipulate a victim into revealing credentials without technical exploitation.

Security Awareness & Training

Question

You work as a technician for Secure Net Inc. You receive an e-mail from your software vendor. The e-mail contains information about a critical fix that needs to be installed on your computer. It further states that if this patch is not installed right away, your system will crash and you will lose all your data. Now they require your maintenance account password. Which of the following types of security attacks do you think it is?

Options

  • ASocial engineering
  • BMan-in-the-middle
  • CHacking
  • DSpoofing

How the community answered

(42 responses)
  • A
    88% (37)
  • B
    2% (1)
  • C
    7% (3)
  • D
    2% (1)

Why each option

This scenario describes social engineering - an attacker uses urgency, fear, and impersonation to manipulate a victim into revealing credentials without technical exploitation.

ASocial engineeringCorrect

Social engineering is a non-technical attack that relies on psychological manipulation - using fear of data loss and urgency to pressure the victim into divulging their maintenance account password. The attacker impersonates a trusted software vendor to establish credibility. No technical system compromise is involved; the attack vector is human psychology and deception.

BMan-in-the-middle

A man-in-the-middle attack requires an attacker to intercept communications between two parties at the network level, which is not described here.

CHacking

Hacking involves technical exploitation of system vulnerabilities or misconfigurations, whereas this attack relies entirely on deception and persuasion.

DSpoofing

Spoofing involves falsifying a source identity at a technical level (such as IP or email header spoofing) as a means to an end, but the core attack mechanism here is psychological manipulation, not identity falsification.

Concept tested: Social engineering credential harvesting via urgency and impersonation

Source: https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks

Topics

#social engineering#phishing#pretexting#email attack

Community Discussion

No community discussion yet for this question.

Full GSLC Practice