exam questions

Exam CAS-003 All Questions

View all questions & answers for the CAS-003 exam

Exam CAS-003 topic 1 question 9 discussion

Actual exam question from CompTIA's CAS-003
Question #: 9
Topic #: 1
[All CAS-003 Questions]

A penetration tester has been contracted to conduct a physical assessment of a site. Which of the following is the MOST plausible method of social engineering to be conducted during this engagement?

  • A. Randomly calling customer employees and posing as a help desk technician requiring user password to resolve issues
  • B. Posing as a copier service technician and indicating the equipment had ג€phoned homeג€ to alert the technician for a service call
  • C. Simulating an illness while at a client location for a sales call and then recovering once listening devices are installed
  • D. Obtaining fake government credentials and impersonating law enforcement to gain access to a company facility
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
twintech
Highly Voted 5 years, 1 month ago
Its B , conduct a physical assessment, also they have asked for a plausible one. calling the employees is not a part of physical assessment. try an illness will attract too much attention and they will likely send you to a hospital. whereas posing a police officer is not legal
upvoted 5 times
...
phatboy
Highly Voted 5 years, 4 months ago
It is definitely not A, this would not give physical access. I think the best answer is B.
upvoted 5 times
...
RaATX
Most Recent 2 years, 10 months ago
Selected Answer: B
Its B. We want to do a physical assessment of the site, so gaining physical access by acting like a copier tech would do it.
upvoted 1 times
...
cvMikazuki
3 years, 7 months ago
B is correct
upvoted 3 times
...
Junbug
4 years, 1 month ago
I say A. "The definition of plausible is something that is highly likely." It is HIGHLY likely someone would pose as a Help Desk Technician requiring user password to resolve issues. Oldest play in the book, taking a chance of actually going to a site and risking the camera capturing your face is not a good idea and it is NOT plausible.
upvoted 1 times
...
Mara03
4 years, 2 months ago
As others already said: the hint is "physical" so B is correct.
upvoted 4 times
...
TheThreatGuy
4 years, 4 months ago
B is definitely correct.
upvoted 3 times
...
Lecky
4 years, 7 months ago
What is the actual Answer?
upvoted 1 times
Trap_D0_r
4 years, 4 months ago
Definitely B. A has nothing to do with a physical assessment. B will validate that the site is physically secure--if someone shows up claiming to be a copy technician their job and service order should be validated before they're allowed into the building, probably with a badge and definitely signing in at reception. As stated earlier, simulating illness would not be an effective strategy and impersonating LEO is highly illegal. There is nothing illegal about pretending to fix copy machines.
upvoted 3 times
...
...
boblee
4 years, 8 months ago
B. IS the answer here.
upvoted 2 times
...
Romex
4 years, 11 months ago
The Answer for me is B. The scenario has to align with the Question. .....emphasis is "gain physical access"
upvoted 2 times
...
zgwy1234
4 years, 11 months ago
The question starts at Which of the following...the most plausible method of social engineering would be A from the list...don't get hanged-up on the entire question as the scenario is trying to throw you off...break the question up.
upvoted 1 times
...
PDVS
5 years, 1 month ago
It also states social engineering - posing as a repairman is not social engineering but posing as Tech support would be. A
upvoted 2 times
kpham90
5 years, 1 month ago
Posing as a repairman is definitely a form of social engineering. It's specifically a form of social engineering through impersonation. There are many forms of social engineering, but all attempt to gain a level of trust by exploiting a human element to gain access or obtain information.
upvoted 4 times
PDVS
5 years ago
I only disagree as Physical access and Social engineering in security are always separated. This question is the only place I have ever seen it as potentially as the answer. I am still sticking with A.
upvoted 1 times
TheThreatGuy
4 years, 4 months ago
Disagree. Social engineering is manipulating people to gain access to systems/environments. B is 100% the answer. A has nothing to do with a "physical assesment".
upvoted 2 times
...
...
...
...
PDVS
5 years, 1 month ago
Bad Question, - A) would give a pen tester access to the network, but B) is the right answer but a pen tester would not do physical site security.
upvoted 2 times
...
tek
5 years, 3 months ago
I think its A. Social engineering is the act of posing as a known entity to acquire information. In this case - Posing as Helpdesk to gain a password
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...