ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 303 - PT0-002 discussion

Report
Export

ion tester is attempting to get more people from a target company to download and run an executable. Which of the following would be the.. :tive way for the tester to achieve this objective?

A.
Dropping USB flash drives around the company campus with the file on it
Answers
A.
Dropping USB flash drives around the company campus with the file on it
B.
Attaching the file in a phishing SMS that warns users to execute the file or they will be locked out of their accounts
Answers
B.
Attaching the file in a phishing SMS that warns users to execute the file or they will be locked out of their accounts
C.
Sending a pretext email from the IT department before sending the download instructions later
Answers
C.
Sending a pretext email from the IT department before sending the download instructions later
D.
Saving the file in a common folder with a name that encourages people to click it
Answers
D.
Saving the file in a common folder with a name that encourages people to click it
Suggested answer: C

Explanation:

The most effective way for the tester to achieve this objective is to send a pretext email from the IT department before sending the download instructions later. A pretext email is an email that uses deception or impersonation to trick users into believing that it is from a legitimate source or authority, such as the IT department. A pretext email can be used to establish trust or rapport with the users, and then persuade them to perform an action or provide information that benefits the attacker. In this case, the tester can send a pretext email from the IT department that informs users about an important update or maintenance task that requires them to download and run an executable file later. The tester can then send another email with the download instructions and attach or link to the malicious executable file. The users may be more likely to follow these instructions if they have received a prior email from the IT department that prepared them for this action. The other options are not as effective ways for the tester to achieve this objective. Dropping USB flash drives around the company campus with the file on it may not reach many users, as they may not find or pick up the USB flash drives, or they may be suspicious of their origin or content.

asked 02/10/2024
Borat Kajratov
49 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first