Skip to content

CMA Foundation · Fundamentals of Business Laws and Business Communication · Internet-based Business Communication

Ravi, an accounts executive, gets a call from someone claiming to be the company's IT helpdesk, who asks for his login password to 'fix a server fault'. Ravi refuses and reports the call. Which security threat did he correctly avoid, and what is its nature?

Ravi avoided social engineering. This threat manipulates people psychologically, often by impersonating trusted staff, into revealing confidential information such as passwords. It exploits human trust rather than technical flaws. A denial-of-service attack floods systems with traffic, and a virus is malicious software, neither involving a persuasive request.

  1. AA virus that physically damages the hard disk
  2. BA denial-of-service attack that floods the server with traffic
  3. CSocial engineering, which manipulates people into revealing confidential informationCorrect
  4. DEncryption of data using a public key

Explanation

The caller exploited trust and used a false identity to extract a password, which is social engineering targeting human behaviour. A denial-of-service attack overloads systems with traffic and involves no request for a password. A virus is malicious software, and public-key encryption is a protective tool, not a threat.

Did you get it right without looking?

One question tells you little. A timed set on Internet-based Business Communication shows your real accuracy, how long you take and where you lose marks.

More Internet-based Business Communication questions