CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium

A caller identifies themselves as a technician from the company's IT helpdesk and tells an employee that their computer has been flagged for a critical security update. The caller convinces the employee to provide their network login credentials 'to verify identity' before proceeding. Which social engineering technique primarily describes the caller's approach?

  1. APretexting
  2. BVishing
  3. CTailgating
  4. DShoulder surfing
Show answer & explanation

Correct answer: A. Pretexting

Pretexting is the use of a fabricated scenario or false identity (posing as IT support) to manipulate a victim into divulging information. While the call itself is a phone-based interaction, the defining technique tested here is the fabricated pretext/story used to justify the credential request, distinguishing it from vishing, which broadly refers to any voice-based phishing regardless of the specific manipulation tactic used.

Why the other options are wrong

  • B. Plausible but less precise: vishing is the general voice-channel phishing category; pretexting names the specific manipulation tactic used.
  • C. Wrong: tailgating involves physically following someone into a restricted area.
  • D. Wrong: shoulder surfing involves visually observing someone entering credentials.

Pretexting

A social engineering technique where an attacker fabricates a believable false scenario or identity to manipulate a victim into revealing information or performing an action.

  • Often combined with vishing, phishing, or impersonation
  • Relies on establishing false trust or authority
  • Common pretexts include IT support, auditors, or executives

Memory trick: Pretexting is the script; vishing is the stage (the phone call).

More Threats, Vulnerabilities, and Mitigations questions