2.5 Compare and contrast common social engineering attacks, threats, and vulnerabilities.
Objective 2.5 sits in Security, which carries 28% of the A+ Core 2 exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.
Objective title verbatim from the official objectives. CompTIA exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
A network administrator configures Windows Firewall with IPsec so that any device attempting to connect must first authenticate as trusted. Devices that fail this check cannot communicate with the host. Which threat does this setting primarily address?
The concept
IPsec authentication in Windows Firewall verifies that a communicating device is genuinely trusted before allowing traffic, which directly counters attempts to fake that trust.
Why this answer
Requiring authentication before communication is permitted exists specifically to stop a device from falsely presenting itself as a trusted source, which is what spoofing describes.
- Correct: spoofing involves falsifying an identity to appear trusted, exactly what the authentication check is designed to catch.
- BWhaling is a phishing attack aimed at a high-value individual through email or messaging, not a network authentication bypass.
- CTailgating is a physical security concern involving following someone through a locked door, unrelated to network authentication.
- DDumpster diving involves retrieving discarded paper or media for information, not connecting to a network as a false identity.
Now you: objective 2.5 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 2
An attacker attaches a packet analyzer to an office network to capture data flowing between two workstations in plaintext. Which attack is occurring, one that encrypting the traffic is designed to prevent?
Sample question 2 of 2
A user clicks a link in an email that appears to come from the IT department and enters a password on a fake login page. The account stays protected because sign-in also requires a registered hardware key. Which technique did the attacker use to obtain the password?
Full A+ Core 2 question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.
More objectives in Security
- 2.2 2.2 Given a scenario, configure and apply basic Microsoft Windows OS security settings.
- 2.4 2.4 Summarize types of malware and tools/methods for detection, removal, and prevention.
- 2.6 2.6 Given a scenario, implement procedures for basic small office/home office (SOHO) malware removal.
- 2.7 2.7 Given a scenario, apply workstation security options and hardening techniques.
- 2.11 2.11 Given a scenario, configure relevant security settings in a browser.