nerdexam
CompTIA

SY0-701 · Question #537

Which of the following would most likely be used by attackers to perform credential harvesting?

The correct answer is A. Social engineering. Social engineering is correct because credential harvesting - tricking users into revealing usernames, passwords, or other login details - is almost always achieved through deceptive human manipulation: phishing emails, fake login pages, vishing calls, or pretexting scenarios tha

Submitted by ahmad_uae· Mar 6, 2026Threats, Vulnerabilities, and Mitigations

Question

Which of the following would most likely be used by attackers to perform credential harvesting?

Options

  • ASocial engineering
  • BSupply chain compromise
  • CThird-party software
  • DRainbow table

How the community answered

(34 responses)
  • A
    94% (32)
  • B
    3% (1)
  • C
    3% (1)

Explanation

Social engineering is correct because credential harvesting - tricking users into revealing usernames, passwords, or other login details - is almost always achieved through deceptive human manipulation: phishing emails, fake login pages, vishing calls, or pretexting scenarios that impersonate trusted entities.

Supply chain compromise (B) targets software or hardware pipelines to inject malicious code before delivery; while it can eventually lead to credential theft, it is not the primary tool for harvesting credentials directly from users. Third-party software (C) is a vector for introducing vulnerabilities or malware, but again it is a delivery mechanism rather than a harvesting technique itself. Rainbow tables (D) are used to crack already-obtained password hashes offline - they are a post-breach tool, not a harvesting method.

Memory tip: Think "harvest = human." Credential harvesting targets people through deception (social engineering), not systems or cryptographic attacks. If the question involves tricking someone into giving up their credentials, the answer is almost always social engineering.

Topics

#Social engineering#Credential harvesting#Attack techniques

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice