nerdexam
CompTIA

PT0-002 · Question #366

A penetration tester is performing a social engineering penetration test and was able to create a remote session. Which of the following social engineering techniques was most likely successful?

The correct answer is A. SMS phishing. To create a remote session, a social engineering technique must typically involve tricking a user into executing malicious code or clicking a malicious link. SMS phishing (smishing) is a highly effective method to deliver such payloads, leading to a remote session.

Attacks and Exploits

Question

A penetration tester is performing a social engineering penetration test and was able to create a remote session. Which of the following social engineering techniques was most likely successful?

Options

  • ASMS phishing
  • BDumpster diving
  • CExecutive impersonation attack
  • DBrowser exploitation framework

How the community answered

(25 responses)
  • A
    80% (20)
  • B
    4% (1)
  • C
    4% (1)
  • D
    12% (3)

Why each option

To create a remote session, a social engineering technique must typically involve tricking a user into executing malicious code or clicking a malicious link. SMS phishing (smishing) is a highly effective method to deliver such payloads, leading to a remote session.

ASMS phishingCorrect

SMS phishing (smishing) often involves sending malicious links or attachments via text message that, when clicked or opened, can execute code, leading to the creation of a remote session back to the attacker's machine. This technique directly leverages user interaction to establish connectivity.

BDumpster diving

Dumpster diving is a physical reconnaissance technique used to retrieve discarded documents or information, which does not directly lead to establishing a remote session.

CExecutive impersonation attack

An executive impersonation attack typically involves tricking someone into revealing information or performing an action (e.g., wiring money) via email or phone, but not directly establishing a remote session.

DBrowser exploitation framework

A browser exploitation framework (e.g., BeEF) is a technical tool used for client-side attacks via the browser, but it is the tool used after a social engineering technique (like phishing) successfully directs a user to a malicious page, not the social engineering technique itself.

Concept tested: Social engineering techniques leading to remote access

Topics

#Social Engineering#SMS Phishing#Initial Access#Penetration Testing

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice