CVA CVA Social Engineering & Physical Security Testing 2 — Questions and Answers
Question 1: Which type of phishing attack specifically targets high-level executives or senior management?
- Spear phishing
- Whaling (Correct answer)
- Clone phishing
- Angler phishing
Correct answer: Whaling
Whaling targets C-suite executives and senior leaders with highly tailored phishing attacks, recognizing that they have access to the most sensitive data and authorization capabilities.
Question 2: During a physical security assessment, what is the purpose of testing RFID badge cloning?
- To verify that badge printers are functioning correctly
- To determine if access control cards can be duplicated to enable unauthorized physical access (Correct answer)
- To test whether badges survive physical damage
- To assess badge database synchronization
Correct answer: To determine if access control cards can be duplicated to enable unauthorized physical access
RFID badge cloning tests whether access control cards (especially older 125kHz HID cards) can be duplicated using commercially available readers, enabling unauthorized facility access.
Question 3: What is the goal of a 'pretexting call' to an organization's help desk during a social engineering assessment?
- To test the help desk's average response time
- To determine if help desk staff can be manipulated into resetting credentials or providing access without proper identity verification (Correct answer)
- To identify outdated phone systems
- To assess call recording capabilities
Correct answer: To determine if help desk staff can be manipulated into resetting credentials or providing access without proper identity verification
Help desk pretexting tests whether support staff will bypass identity verification procedures when presented with a convincing false scenario, potentially resetting credentials for an attacker.
Question 4: Which physical security control is specifically designed to prevent tailgating by allowing only one person to enter per authentication event?
- Security camera
- Mantrap (airlock) (Correct answer)
- Biometric reader
- Motion sensor
Correct answer: Mantrap (airlock)
A mantrap (airlock) uses two interlocking doors where only one can open at a time, ensuring that only the authenticated individual can enter the secured area.
Question 5: What is 'open-source intelligence (OSINT)' and how is it used in social engineering assessments?
- Accessing classified government databases for target profiling
- Gathering publicly available information about targets from social media, websites, and public records to craft convincing attacks (Correct answer)
- Using open-source security tools to scan target networks
- Reviewing open-source code for vulnerabilities
Correct answer: Gathering publicly available information about targets from social media, websites, and public records to craft convincing attacks
OSINT collection from LinkedIn, social media, company websites, and public records provides attackers with information to craft highly convincing and personalized social engineering attacks.
Question 6: During a physical security walk-through, you notice employees often prop open secured doors for convenience. What control weakness does this represent?
- Insufficient lighting in secured areas
- Door prop detection and security culture failure — access controls are bypassed by user behavior (Correct answer)
- Inadequate visitor management procedures
- Lack of security guard staffing
Correct answer: Door prop detection and security culture failure — access controls are bypassed by user behavior
Propping open secured doors bypasses physical access controls and represents both a technical control failure (no door prop alarms) and a security culture issue requiring awareness training.
Which type of phishing attack specifically targets high-level executives or senior management?