nerdexam
GIAC

GSLC · Question #20

Which of the following are types of social engineering attacks? Each correct answer represents a complete solution. Choose two.

The correct answer is A. An unauthorized person calls a user and pretends to be a system administrator in order to get the D. An unauthorized person gains entrance to the building where the company's database server resides. Social engineering attacks manipulate people through deception or physical means rather than exploiting technical vulnerabilities.

Security Awareness & Training

Question

Which of the following are types of social engineering attacks? Each correct answer represents a complete solution. Choose two.

Options

  • AAn unauthorized person calls a user and pretends to be a system administrator in order to get the
  • BAn unauthorized person inserts an intermediary software or program between two communicating
  • CAn unauthorized person modifies packet headers by using someone else's IP address to hide his
  • DAn unauthorized person gains entrance to the building where the company's database server resides

How the community answered

(30 responses)
  • A
    87% (26)
  • B
    3% (1)
  • C
    10% (3)

Why each option

Social engineering attacks manipulate people through deception or physical means rather than exploiting technical vulnerabilities.

AAn unauthorized person calls a user and pretends to be a system administrator in order to get theCorrect

Impersonating a system administrator over the phone to extract credentials or access is a classic social engineering technique known as pretexting, which exploits human trust rather than technical weaknesses.

BAn unauthorized person inserts an intermediary software or program between two communicating

Inserting intermediary software between two communicating parties describes a man-in-the-middle attack, which is a technical network-based attack, not a social engineering attack.

CAn unauthorized person modifies packet headers by using someone else's IP address to hide his

Modifying packet headers using someone else's IP address describes IP spoofing, which is a technical attack exploiting network protocols, not a manipulation of human behavior.

DAn unauthorized person gains entrance to the building where the company's database server residesCorrect

An unauthorized person physically entering a secured building by exploiting human courtesy or following authorized personnel - known as tailgating or piggybacking - is a social engineering attack that targets people and physical security controls rather than systems.

Concept tested: Social engineering attack types - pretexting and tailgating

Source: https://www.cisa.gov/resources-tools/resources/social-engineering-attacks

Topics

#social engineering#impersonation#tailgating#physical security

Community Discussion

No community discussion yet for this question.

Full GSLC Practice