nerdexam
GIAC

GSLC · Question #228

Which of the following are vulnerable to social engineering attacks? Each correct answer represents a complete solution. Choose two.

The correct answer is A. Minimal trained company employees C. A public building that has shared office space. Social engineering exploits human behavior and weak physical access controls, making untrained employees and publicly accessible spaces the primary targets. Technical safeguards like encryption and biometrics are not defeated by social manipulation.

Security Awareness & Training

Question

Which of the following are vulnerable to social engineering attacks? Each correct answer represents a complete solution. Choose two.

Options

  • AMinimal trained company employees
  • BEncrypted data on the hard disk drive
  • CA public building that has shared office space
  • DAn office with a biometrics authentication system

How the community answered

(49 responses)
  • A
    94% (46)
  • B
    4% (2)
  • D
    2% (1)

Why each option

Social engineering exploits human behavior and weak physical access controls, making untrained employees and publicly accessible spaces the primary targets. Technical safeguards like encryption and biometrics are not defeated by social manipulation.

AMinimal trained company employeesCorrect

Minimally trained employees lack awareness of social engineering tactics such as phishing, pretexting, and baiting, making them susceptible to manipulation by attackers impersonating trusted figures.

BEncrypted data on the hard disk drive

Encrypted data on a hard disk drive is protected by a cryptographic technical control that cannot be bypassed by deception - an attacker cannot talk their way past encryption algorithms.

CA public building that has shared office spaceCorrect

A public building with shared office space lacks strict access control, enabling tailgating, shoulder surfing, and impersonation attacks because strangers can enter without challenge.

DAn office with a biometrics authentication system

A biometrics authentication system enforces access using verified biological traits, making it resistant to social impersonation because no amount of manipulation can substitute for the required physical characteristic.

Concept tested: Social engineering attack vectors targeting humans and physical access

Source: https://csrc.nist.gov/glossary/term/social_engineering

Topics

#social engineering#human vulnerability#physical security#employee awareness

Community Discussion

No community discussion yet for this question.

Full GSLC Practice