ITPEC FE Morning October 2022 Question 41

Source exam: ITPEC FE Morning October 2022Topic: Security

ITPEC FE Morning October 2022 — Question 41 of 80

Social Engineering — tricking people into revealing confidential information.

An attacker calls the help desk pretending to be an employee who forgot their password. The staff resets it to a default, and the attacker uses it to access the network.

Answer: d) Social engineering

  • Social engineering — manipulating people (not systems) to gain unauthorized access
  • The attacker exploits human trust, not a technical vulnerability

Why not others:
- (a) Buffer overflow — exploits memory allocation flaws in software

- (b) Denial-of-Service — floods a service with traffic to make it unavailable

- (c) Shoulder surfing — physically observing someone entering sensitive data

Key rule: If the attack relies on deceiving a person rather than exploiting code or infrastructure, it is social engineering.

AI-generated — may contain errors

The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.

This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official FE past-paper collection or Report an issue.