GSLC · Question #351
In which type of person-to-person attack does an attacker pretend to be someone else?
The correct answer is C. Impersonation. Impersonation is the social engineering technique where an attacker falsely claims to be another person to manipulate a victim into granting access or disclosing sensitive information.
Question
In which type of person-to-person attack does an attacker pretend to be someone else?
Options
- AIn Person Attack
- BImportant User Posing
- CImpersonation
- DThird-Party Authorization
How the community answered
(17 responses)- A6% (1)
- B6% (1)
- C88% (15)
Why each option
Impersonation is the social engineering technique where an attacker falsely claims to be another person to manipulate a victim into granting access or disclosing sensitive information.
In Person Attack is a broad physical security category describing face-to-face interactions generally, not the specific act of falsely claiming another identity.
Important User Posing is not a recognized or standardized cybersecurity attack classification.
Impersonation is a recognized person-to-person social engineering attack in which the attacker adopts a false identity - such as an IT helpdesk technician, executive, or vendor - to exploit the victim's trust or deference to authority. Unlike phishing, impersonation occurs through direct human interaction and relies on psychological manipulation rather than technical exploitation.
Third-Party Authorization is a legitimate security and identity delegation mechanism, not a social engineering attack type.
Concept tested: Social engineering impersonation attack definition
Source: https://csrc.nist.gov/glossary/term/impersonation
Topics
Community Discussion
No community discussion yet for this question.