220-1102 Question 429
Single answerSocial engineeringA help desk technician receives a call from someone claiming to be the company's CFO, who says she is traveling and urgently needs her password reset so she can review payroll before a board meeting. The caller knows the CFO's full name, department, and executive assistant's name, and pressures the technician by saying, "If this isn't fixed in 5 minutes, people won't get paid." Company policy requires identity verification through a callback to the executive contact number on file or approval from the CFO's assistant in the ticketing system. What should the technician do FIRST?
- A
Reset the password immediately because payroll is business-critical and the caller knew internal details
- B
Ask the caller to provide her employee ID and last four digits of her Social Security number, then reset the password if they match
- C
Follow the verification process by calling the executive contact number on file or obtaining approval through the ticketing system before making any account changes
- D
Escalate the request directly to the security team and refuse to assist with executive password resets
Show answer and explanation
Correct answer: C
Explanation
This scenario tests recognition of social engineering tactics in a realistic support environment. The caller uses authority impersonation, urgency, and intimidation to get the technician to ignore policy. These are common indicators of social engineering covered in CompTIA A+ Core 2 objectives. The correct response is to follow documented identity verification procedures before performing sensitive actions such as password resets. Best practices from organizational security policies and general guidance from sources such as NIST identity and access management recommendations emphasize verifying identity through trusted channels, using approved workflows, and avoiding reliance on easily obtained personal details. In practice, help desk staff should resist pressure, document the interaction, and escalate only if the behavior appears malicious or the caller refuses standard verification.
- A. Incorrect.
Incorrect. This is a classic social engineering scenario using urgency, authority, and insider information to pressure the technician into bypassing procedure. Knowing internal details does not prove identity because attackers often gather this information from public sources, phishing, social media, or prior breaches. Resetting the password without verification violates policy and could lead to account compromise.
- B. Incorrect.
Incorrect. Although additional questions may seem reasonable, this option is weaker than following the documented verification method. Personal identifiers such as employee ID or partial SSN are not reliable authentication factors in many organizations because they may be discoverable or previously exposed. The scenario explicitly states the approved verification methods, so the technician should use those instead of ad hoc identity checks.
- C. Correct.
Correct. The safest and most appropriate first action is to follow the organization's documented identity verification process before changing credentials. This directly addresses the social engineering risk by relying on trusted contact information and established workflow controls rather than caller claims. In A+ Core 2, technicians are expected to recognize social engineering indicators and adhere to security policy even when the request appears urgent or comes from an executive.
- D. Incorrect.
Incorrect. Escalation to security may be appropriate if the caller becomes suspicious, abusive, or continues attempting to bypass policy, but it is not the best first step based on the scenario. The technician still has a defined process for handling the request. Refusing all executive password resets is also not practical; the key is to complete them only after proper verification.