Home > CompTIA PenTest+ Certification > Quizzes > CompTIA PenTest+ Certification Exam: Social Engineering and Physical Attacks
CompTIA PenTest+ Certification Exam: Social Engineering and Physical Attacks
Fast practice, instant feedback. Timer auto-submits when time’s up.
Avg score: 72% Most missed: “Select type/s of social engineering attacks that use URLs to send targets to web…”
CompTIA PenTest+ Certification Exam: Social Engineering and Physical Attacks
Time left 00:00
9 Questions

1. Many types of countermeasures can help organizations prepare for and mitigate potential social engineering attacks. Which of the following are valid countermeasures for social engineering attacks?
2. Alice owns a very profitable consultant firm that handles a great deal of privacy information for her clients. The company has over 50 employees but outsources their IT services to another company. One afternoon while Alice was at lunch, her receptionist received a phone call from a person claiming to be from the IT service provider and saying that they are trying to work on a service ticket for Alice and that they need her personal cell phone number in order to ask some questions of a private nature. The receptionist knows that Alice doesn’t have any computer problems. What type of social engineering attack did Alice’s receptionist receive?
3. ___________ is a type of social engineering technique that can be used to exploit physical access controls in order to gain unauthorized access to a restricted area when an authorized individual consented to the entry.
4. Alice owns a very profitable consultant firm that handles a great deal of privacy information for her clients. The company has over 50 employees but outsources their IT services to another company. One afternoon while Alice was at lunch, her receptionist received a phone call from a person claiming to be from the IT service provider and saying that they are trying to work on a service ticket for Alice and that they need her personal cell phone number in order to ask some questions of a private nature. The receptionist knows that Alice doesn’t have any computer problems. What type of social engineering attack did Alice’s receptionist receive?
5. Select type/s of social engineering attacks that use URLs to send targets to web pages for further attacks against the computer network.
6. Many types of countermeasures can help organizations prepare for and mitigate potential social engineering attacks. Which of the following are valid countermeasures for social engineering attacks?
7. The Social-Engineer Toolkit (SET) is a Python-based framework that can do which of the following?
8. Criminal impersonation is governed by state laws and is a crime that can involve identity theft, impersonating an officer or legal counsel, and many other avenues of attack that involve a plot to defraud another by pretending to be someone you are not. Which two documents could you consult to determine if the social engineering attack you would like to use during an engagement is approved by the organization?
9. The Physical and Environmental Security domain from NIST SP 800-53 (rev 4) provides 20 different access controls that can be applied at different impact levels. All controls applicable to an organization’s physical security scheme need to be assessed; however, when would a control require a technical assessment?