ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 161 - PT0-002 discussion

Report
Export

A private investigation firm is requesting a penetration test to determine the likelihood that attackers can gain access to mobile devices and then exfiltrate data from those devices. Which of the following is a social-engineering method that, if successful, would MOST likely enable both objectives?

A.
Send an SMS with a spoofed service number including a link to download a malicious application.
Answers
A.
Send an SMS with a spoofed service number including a link to download a malicious application.
B.
Exploit a vulnerability in the MDM and create a new account and device profile.
Answers
B.
Exploit a vulnerability in the MDM and create a new account and device profile.
C.
Perform vishing on the IT help desk to gather a list of approved device IMEIs for masquerading.
Answers
C.
Perform vishing on the IT help desk to gather a list of approved device IMEIs for masquerading.
D.
Infest a website that is often used by employees with malware targeted toward x86 architectures.
Answers
D.
Infest a website that is often used by employees with malware targeted toward x86 architectures.
Suggested answer: A

Explanation:

Since it doesn't indicate company owned devices, sending a text to download an application is best.

And it says social-engineering so a spoofed text falls under that area.

asked 02/10/2024
MM rahn
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first