220-1102 Question 428
Single answer2.5 Compare and contrast common social engineering attacks, threats, and vulnerabilities.A help desk technician receives a call from someone claiming to be the company's CFO, who says they are traveling and urgently need their VPN password reset. The caller sounds stressed, insists the request must be completed within the next 5 minutes to finalize a wire transfer, and asks the technician not to call back because they are "about to board a flight." Company policy requires identity verification through a callback to the executive's registered number or approval from the executive assistant. Which social engineering technique is the caller MOST likely using?
- A
Pretexting
- B
Tailgating
- C
Shoulder surfing
- D
Whaling
Show answer and explanation
Correct answer: A
Explanation
The best answer is pretexting because the attacker is using a fabricated identity and urgent business scenario to convince the technician to violate account recovery policy. This is a classic social engineering pattern: impersonation, authority, urgency, and an attempt to bypass verification controls. In real-world environments, help desk staff should follow documented identity verification procedures for password resets, especially for privileged or executive accounts, and should not allow urgency or rank to override policy. This aligns with common security awareness guidance from organizations such as NIST, which emphasizes verification, least privilege, and adherence to established processes to resist social engineering.
- A. Correct.
Correct. Pretexting involves creating a fabricated but believable scenario to manipulate a target into disclosing information or performing an action. In this case, the caller invents an urgent executive travel scenario, applies pressure, and attempts to bypass established verification procedures. The attack relies on the false identity and story rather than technical compromise.
- B. Incorrect.
Incorrect. Tailgating is a physical security attack in which an unauthorized person follows an authorized person into a restricted area without proper authentication. This scenario is over the phone and focuses on impersonation and urgency, not physical access control.
- C. Incorrect.
Incorrect. Shoulder surfing involves observing someone entering credentials or viewing sensitive information, typically by looking over their shoulder or via nearby surveillance. The scenario does not involve visual observation of information entry.
- D. Incorrect.
Incorrect. Whaling is a targeted phishing or social engineering attack aimed specifically at high-profile executives or decision-makers. While the attacker is impersonating a CFO, the target of the attack is the help desk technician, and the defining characteristic here is the invented story used to obtain a password reset. Someone might choose this option because an executive is mentioned, but the technique being used is pretexting.