CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium
A caller identifies themselves as a technician from the company's IT helpdesk and tells an employee that their computer has been flagged for a critical security update. The caller convinces the employee to provide their network login credentials 'to verify identity' before proceeding. Which social engineering technique primarily describes the caller's approach?
- APretexting
- BVishing
- CTailgating
- DShoulder surfing
Show answer & explanationAnswer & explanation
Correct answer: A. Pretexting
Pretexting is the use of a fabricated scenario or false identity (posing as IT support) to manipulate a victim into divulging information. While the call itself is a phone-based interaction, the defining technique tested here is the fabricated pretext/story used to justify the credential request, distinguishing it from vishing, which broadly refers to any voice-based phishing regardless of the specific manipulation tactic used.
Why the other options are wrong
- B. Plausible but less precise: vishing is the general voice-channel phishing category; pretexting names the specific manipulation tactic used.
- C. Wrong: tailgating involves physically following someone into a restricted area.
- D. Wrong: shoulder surfing involves visually observing someone entering credentials.
Pretexting
A social engineering technique where an attacker fabricates a believable false scenario or identity to manipulate a victim into revealing information or performing an action.
- Often combined with vishing, phishing, or impersonation
- Relies on establishing false trust or authority
- Common pretexts include IT support, auditors, or executives
Memory trick: Pretexting is the script; vishing is the stage (the phone call).