GSLC · Question #178
You work as a technician for Secure Net Inc. You receive an e-mail from your software vendor. The e-mail contains information about a critical fix that needs to be installed on your computer. It…
The correct answer is A. Social engineering. This scenario describes social engineering - an attacker uses urgency, fear, and impersonation to manipulate a victim into revealing credentials without technical exploitation.
Question
You work as a technician for Secure Net Inc. You receive an e-mail from your software vendor. The e-mail contains information about a critical fix that needs to be installed on your computer. It further states that if this patch is not installed right away, your system will crash and you will lose all your data. Now they require your maintenance account password. Which of the following types of security attacks do you think it is?
Options
- ASocial engineering
- BMan-in-the-middle
- CHacking
- DSpoofing
How the community answered
(42 responses)- A88% (37)
- B2% (1)
- C7% (3)
- D2% (1)
Why each option
This scenario describes social engineering - an attacker uses urgency, fear, and impersonation to manipulate a victim into revealing credentials without technical exploitation.
Social engineering is a non-technical attack that relies on psychological manipulation - using fear of data loss and urgency to pressure the victim into divulging their maintenance account password. The attacker impersonates a trusted software vendor to establish credibility. No technical system compromise is involved; the attack vector is human psychology and deception.
A man-in-the-middle attack requires an attacker to intercept communications between two parties at the network level, which is not described here.
Hacking involves technical exploitation of system vulnerabilities or misconfigurations, whereas this attack relies entirely on deception and persuasion.
Spoofing involves falsifying a source identity at a technical level (such as IP or email header spoofing) as a means to an end, but the core attack mechanism here is psychological manipulation, not identity falsification.
Concept tested: Social engineering credential harvesting via urgency and impersonation
Source: https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks
Topics
Community Discussion
No community discussion yet for this question.