Skip to content

CMA Foundation · Fundamentals of Business Laws and Business Communication · Internet-based Business Communication

An employee of Sundaram Traders gets a call from a person claiming to be from the company's IT help desk, who persuades her to reveal her login OTP by creating urgency and trust. No software flaw was exploited. This incident is best classified as:

The incident is social engineering. The attacker manipulated the employee through false authority, trust and urgency to get her to reveal an OTP, exploiting human behaviour rather than a technical weakness. Denial-of-service, brute-force guessing and firewall-based malware attacks all rely on technical methods that were absent here.

  1. AA denial-of-service attack
  2. BSocial engineeringCorrect
  3. CA brute-force password attack
  4. DMalware infection through a firewall breach

Explanation

Social engineering manipulates people psychologically into disclosing confidential information; here trust and urgency were used and no technical flaw was exploited. A denial-of-service attack floods a system, brute force guesses passwords repeatedly, and malware via firewall breach involves technical intrusion, none of which occurred.

Did you get it right without looking?

One question tells you little. A timed set on Internet-based Business Communication shows your real accuracy, how long you take and where you lose marks.

More Internet-based Business Communication questions