nerdexam
CompTIA

SY0-301 · Question #217

Purchasing receives a phone call from a vendor asking for a payment over the phone. The phone number displayed on the caller ID matches the vendor's number. When the purchasing agent asks to call…

The correct answer is B. Impersonation. Impersonation is the act of pretending to be someone else - in this case, a legitimate vendor - to manipulate a victim into taking a harmful action (making a fraudulent payment). The attacker spoofed the vendor's caller ID to appear legitimate, then provided a different…

Threats, vulnerabilities, and mitigations

Question

Purchasing receives a phone call from a vendor asking for a payment over the phone. The phone number displayed on the caller ID matches the vendor's number. When the purchasing agent asks to call the vendor back, they are given a different phone number with a different area code. Which of the following attack types is this?

Options

  • AHoax
  • BImpersonation
  • CSpear phishing
  • DWhaling

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    92% (24)
  • C
    4% (1)

Explanation

Impersonation is the act of pretending to be someone else - in this case, a legitimate vendor - to manipulate a victim into taking a harmful action (making a fraudulent payment). The attacker spoofed the vendor's caller ID to appear legitimate, then provided a different callback number (their own) when challenged. This is a social engineering impersonation attack. It is not Spear Phishing (Option C), which is a targeted email attack. It is not Whaling (Option D), which targets high-level executives. It is not a Hoax (Option A), which is typically a false warning or alarm rather than an active deceptive call designed to extract payment.

Topics

#impersonation#social engineering#caller ID spoofing#pretexting

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice