nerdexam
CompTIA

SY0-301 · Question #144

Pete's corporation has outsourced help desk services to a large provider. Management has published a procedure that requires all users, when receiving support, to call a special number. Users then…

The correct answer is B. Impersonation. The code exchange is a mutual authentication mechanism: the legitimate help desk provides a code first, which the user enters before granting access. This prevents an attacker from calling a user, pretending to be help desk support, and tricking the user into granting remote…

Threats, vulnerabilities, and mitigations

Question

Pete's corporation has outsourced help desk services to a large provider. Management has published a procedure that requires all users, when receiving support, to call a special number. Users then need to enter the code provided to them by the help desk technician prior to allowing the technician to work on their PC. Which of the following does this procedure prevent?

Options

  • ACollusion
  • BImpersonation
  • CPharming
  • DTransitive Access

How the community answered

(47 responses)
  • A
    9% (4)
  • B
    87% (41)
  • C
    2% (1)
  • D
    2% (1)

Explanation

The code exchange is a mutual authentication mechanism: the legitimate help desk provides a code first, which the user enters before granting access. This prevents an attacker from calling a user, pretending to be help desk support, and tricking the user into granting remote access - a classic impersonation (vishing) attack. Collusion (A) is insiders conspiring together. Pharming (C) redirects DNS to fraudulent sites. Transitive access (D) refers to trust relationships between systems.

Topics

#impersonation#social engineering#help desk security#identity verification

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice