CompTIA PT0-002 Practice Test 5
Question 1 / 40
A private investigation firm is requesting a penetration test to determine the likelihood that attackers can gain access to mobile devices and then exfiltrate data from those devices. Which of the following is a social-engineering method that, if successful, would MOST likely enable both objectives?
Send an SMS with a spoofed service number including a link to download a malicious application.
Exploit a vulnerability in the MDM and create a new account and device profile.
Perform vishing on the IT help desk to gather a list of approved device IMEIs for masquerading.
Infest a website that is often used by employees with malware targeted toward x86 architectures.
Comment (0)
Suggested answer: A
Explanation:
Since it doesn't indicate company owned devices, sending a text to download an application is best.
And it says social-engineering so a spoofed text falls under that area.