nerdexam
CompTIA

SY0-301 · Question #703

A database administrator receives a call on an outside telephone line from a person who states that they work for a well-known database vendor. The caller states there have been problems applying…

The correct answer is A. Thank the caller, report the contact to the manager, and contact the vendor support line to verify any. This scenario describes a classic social engineering / pretexting attack. The caller is attempting to extract sensitive system information (version and patch level) under a pretense of helpfulness. The correct response is to never provide sensitive information to an unverified…

Threats, vulnerabilities, and mitigations

Question

A database administrator receives a call on an outside telephone line from a person who states that they work for a well-known database vendor. The caller states there have been problems applying the newly released vulnerability patch for their database system, and asks what version is being used so that they can assist. Which of the following is the BEST action for the administrator to take?

Options

  • AThank the caller, report the contact to the manager, and contact the vendor support line to verify any
  • BObtain the vendor's email and phone number and call them back after identifying the number of systems
  • CGive the caller the database version and patch level so that they can receive help applying the patch.
  • DCall the police to report the contact about the database systems, and then check system logs for attack

How the community answered

(69 responses)
  • A
    72% (50)
  • B
    4% (3)
  • C
    7% (5)
  • D
    16% (11)

Explanation

This scenario describes a classic social engineering / pretexting attack. The caller is attempting to extract sensitive system information (version and patch level) under a pretense of helpfulness. The correct response is to never provide sensitive information to an unverified caller, report the incident up the chain of command, and independently verify by calling the vendor's official, publicly listed support number. Option B is partially reasonable but still involves calling back an unverified number. Option C directly gives away sensitive data. Option D (calling police) is an overreaction at this stage.

Topics

#social engineering#vishing#pretexting#security awareness

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice