CMA Foundation · Fundamentals of Business Laws and Business Communication · Internet-based Business Communication
An employee of Sundaram Traders gets a call from a person claiming to be from the company's IT help desk, who persuades her to reveal her login OTP by creating urgency and trust. No software flaw was exploited. This incident is best classified as:
The incident is social engineering. The attacker manipulated the employee through false authority, trust and urgency to get her to reveal an OTP, exploiting human behaviour rather than a technical weakness. Denial-of-service, brute-force guessing and firewall-based malware attacks all rely on technical methods that were absent here.
- AA denial-of-service attack
- BSocial engineeringCorrect
- CA brute-force password attack
- DMalware infection through a firewall breach
Explanation
Social engineering manipulates people psychologically into disclosing confidential information; here trust and urgency were used and no technical flaw was exploited. A denial-of-service attack floods a system, brute force guesses passwords repeatedly, and malware via firewall breach involves technical intrusion, none of which occurred.
Did you get it right without looking?
One question tells you little. A timed set on Internet-based Business Communication shows your real accuracy, how long you take and where you lose marks.
More Internet-based Business Communication questions
- Which feature distinguishes email from a traditional postal letter as a medium of business communication?
- Meera, a manager, is chairing a video meeting. Two participants keep speaking together, a third has a noisy background, and another is readi…
- A manager sends an email to the entire company using 'Reply All' to a message that was sent to 400 employees, only to say 'Noted, thanks'. T…
- Mr. Iyer, a manager at a Chennai firm, wants to send a circular to 300 customers so that no customer sees any other customer's email address…
- A well-written subject line in a business email should be:
- Which of the following is a recognised limitation of video conferencing in business?