A penetration tester recently performed a socialengineering - CompTIA Pentest+ PT0-003

Question

A penetration tester recently performed a social-engineering attack in which the tester found an employee of the target company at a local coffee shop and over time built a relationship with the employee. On the employee's birthday, the tester gave the employee an external hard drive as a gift.
Which of the following social-engineering attacks was the tester utilizing?

Answers
  1. correct
Explanation

Correct Answer: C. Baiting

Baiting is a social engineering attack that involves luring a victim with an appealing item, such as an external hard drive, USB stick, or free software, that contains malicious software. In this scenario, the penetration tester built trust with an employee over time and then gave them an external hard drive as a birthday gift, which is a classic example of a baiting attack.

Why is this Baiting?

  1. The attacker offers an enticing item (external hard drive).
  2. The target voluntarily accepts and connects it to a company system (potentially infecting the network).
  3. The malicious payload is delivered unknowingly (e.g., malware, keylogger, or backdoor).

Why the Other Options Are Incorrect:

Phishing

  • Phishing involves deceptive emails, messages, or websites designed to trick a victim into providing sensitive information.
  • This scenario does not involve emails or messages; instead, it uses a physical device to exploit trust.
    Incorrect because phishing typically happens via digital communication, not in-person manipulation.

Tailgating

  • Tailgating is a physical security attack where an unauthorized person follows an authorized employee into a restricted area.

  • The scenario does not involve physical entry into a secured location.
    Incorrect because it does not involve bypassing physical security.

Shoulder Surfing

  • Shoulder surfing occurs when an attacker observes a victim entering credentials or sensitive information (e.g., PINs, passwords, or data) over their shoulder.

  • There is no mention of observing sensitive information in this scenario.
     Incorrect because the attacker did not watch the employee enter sensitive data.

No Payment Cards Needed

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA SecurityX CAS-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud Essentials+ CLO-002

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Network+ N10-009

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Security+ SY0-701

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Linux+ XK0-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA CySA+ CSO-003

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud+ CV0-004

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered