CVA CVA Social Engineering & Physical Security Testing 1 — Questions and Answers
Question 1: Which social engineering technique involves impersonating a trusted authority figure via phone to extract sensitive information from an employee?
- Phishing
- Vishing (Correct answer)
- Smishing
- Pretexting
Correct answer: Vishing
Vishing (voice phishing) uses phone calls where attackers impersonate IT support, executives, or other authorities to manipulate employees into revealing credentials or sensitive data.
Question 2: During a physical security assessment, what is 'tailgating' (piggybacking)?
- Following an authorized person through a secured access-controlled door without using credentials (Correct answer)
- Installing a keylogger on an unattended workstation
- Cloning an employee's RFID badge
- Intercepting wireless network traffic
Correct answer: Following an authorized person through a secured access-controlled door without using credentials
Tailgating occurs when an unauthorized individual follows closely behind an authorized person to gain physical access to a restricted area without using their own credentials.
Question 3: What is 'pretexting' in the context of social engineering assessments?
- Sending malicious email attachments
- Creating a fabricated scenario or false identity to manipulate a target into providing information or access (Correct answer)
- Setting up a rogue wireless access point
- Intercepting and modifying network communications
Correct answer: Creating a fabricated scenario or false identity to manipulate a target into providing information or access
Pretexting involves crafting a believable false scenario or identity (e.g., IT auditor, delivery person) to gain the target's trust and extract sensitive information or physical access.
Question 4: Which attack involves sending fraudulent text messages to trick recipients into clicking malicious links or providing sensitive information?
- Vishing
- Whaling
- Smishing (Correct answer)
- Spear phishing
Correct answer: Smishing
Smishing (SMS phishing) uses text messages to deliver malicious links or pretexts designed to steal credentials, install malware, or extract sensitive information.
Question 5: During a physical security assessment, what does 'dumpster diving' evaluate?
- Network traffic from discarded devices
- Whether sensitive information is discarded in an accessible manner without proper destruction (Correct answer)
- Whether building dumpsters have adequate fire suppression
- Employee physical fitness compliance
Correct answer: Whether sensitive information is discarded in an accessible manner without proper destruction
Dumpster diving assesses whether an organization properly destroys sensitive documents and media before disposal, as improperly discarded information can aid attackers.
Question 6: What is 'baiting' in a social engineering context?
- Sending targeted spear-phishing emails to executives
- Leaving infected physical media (USB drives) in locations where employees may find and use them (Correct answer)
- Impersonating a vendor during a phone call
- Creating a fake login portal to capture credentials
Correct answer: Leaving infected physical media (USB drives) in locations where employees may find and use them
Baiting uses infected physical media like USB drives left in parking lots or common areas to tempt employees into plugging them into corporate systems.
Which social engineering technique involves impersonating a trusted authority figure via phone to extract sensitive information from an employee?