ITPEC FE Subject A October 2025 Question 27

Source exam: ITPEC FE Subject A October 2025Topic: Security

ITPEC FE Subject A October 2025 — Question 27 of 60

Baiting attack — social engineering attack using a physical lure (e.g., infected USB drive) to trick victims into compromising their systems.

The attacker left a malware-loaded USB stick labeled with an enticing title in front of an office, hoping someone would plug it in out of curiosity. This is baiting — using a physical object as a trap.

Why not others:
- (b) Identity theft — stealing someone's personal information to impersonate them; this is a consequence, not an attack method

- (c) Phishing — tricking victims via fraudulent emails or websites; no electronic communication is involved here

- (d) Pretexting — creating a fabricated scenario (e.g., posing as IT support) to extract information through conversation; no personal interaction occurs here

Key rule: physical lure left for the victim to find = baiting; deceptive email/website = phishing; fabricated story in direct communication = pretexting.

AI-generated — may contain errors

The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.

This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official FE past-paper collection or Report an issue.