Objective 2.5220-1202

2.5 Compare and contrast common social engineering attacks, threats, and vulnerabilities.

Objective 2.5 sits in Security, which carries 28% of the A+ Core 2 exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.

Objective title verbatim from the official objectives. CompTIA exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

SecurityEasy

A network administrator configures Windows Firewall with IPsec so that any device attempting to connect must first authenticate as trusted. Devices that fail this check cannot communicate with the host. Which threat does this setting primarily address?

Correct.

The concept

IPsec authentication in Windows Firewall verifies that a communicating device is genuinely trusted before allowing traffic, which directly counters attempts to fake that trust.

Why this answer

Requiring authentication before communication is permitted exists specifically to stop a device from falsely presenting itself as a trusted source, which is what spoofing describes.

  • Correct: spoofing involves falsifying an identity to appear trusted, exactly what the authentication check is designed to catch.
  • BWhaling is a phishing attack aimed at a high-value individual through email or messaging, not a network authentication bypass.
  • CTailgating is a physical security concern involving following someone through a locked door, unrelated to network authentication.
  • DDumpster diving involves retrieving discarded paper or media for information, not connecting to a network as a false identity.
Read the sourceMicrosoft Learn: Windows Firewall
Source-cited
social engineeringspoofingipsecauthentication

Now you: objective 2.5 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 2

SecurityModerate

An attacker attaches a packet analyzer to an office network to capture data flowing between two workstations in plaintext. Which attack is occurring, one that encrypting the traffic is designed to prevent?

Sample question 2 of 2

SecurityModerate

A user clicks a link in an email that appears to come from the IT department and enters a password on a fake login page. The account stays protected because sign-in also requires a registered hardware key. Which technique did the attacker use to obtain the password?

Full A+ Core 2 question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Security