PT0-002 · Question #366
A penetration tester is performing a social engineering penetration test and was able to create a remote session. Which of the following social engineering techniques was most likely successful?
The correct answer is A. SMS phishing. To create a remote session, a social engineering technique must typically involve tricking a user into executing malicious code or clicking a malicious link. SMS phishing (smishing) is a highly effective method to deliver such payloads, leading to a remote session.
Question
A penetration tester is performing a social engineering penetration test and was able to create a remote session. Which of the following social engineering techniques was most likely successful?
Options
- ASMS phishing
- BDumpster diving
- CExecutive impersonation attack
- DBrowser exploitation framework
How the community answered
(25 responses)- A80% (20)
- B4% (1)
- C4% (1)
- D12% (3)
Why each option
To create a remote session, a social engineering technique must typically involve tricking a user into executing malicious code or clicking a malicious link. SMS phishing (smishing) is a highly effective method to deliver such payloads, leading to a remote session.
SMS phishing (smishing) often involves sending malicious links or attachments via text message that, when clicked or opened, can execute code, leading to the creation of a remote session back to the attacker's machine. This technique directly leverages user interaction to establish connectivity.
Dumpster diving is a physical reconnaissance technique used to retrieve discarded documents or information, which does not directly lead to establishing a remote session.
An executive impersonation attack typically involves tricking someone into revealing information or performing an action (e.g., wiring money) via email or phone, but not directly establishing a remote session.
A browser exploitation framework (e.g., BeEF) is a technical tool used for client-side attacks via the browser, but it is the tool used after a social engineering technique (like phishing) successfully directs a user to a malicious page, not the social engineering technique itself.
Concept tested: Social engineering techniques leading to remote access
Topics
Community Discussion
No community discussion yet for this question.