Objective 5.4CC

5.4 Understand security awareness training.

Objective 5.4 sits in Security Operations, which carries 18% of the Certified in Cybersecurity exam. The questions below are original, written from the official objective title above, and each explanation cites the ISC2 page it rests on.

Objective title verbatim from the official objectives. ISC2 exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

5-4Security OperationsEasy

What defines a social engineering attack?

Malware injected into a web serverServer-side malware is a technical intrusion, no conversation required.
Radio interception of wireless trafficInterception is passive eavesdropping, the right answer for a sniffing question.
Brute force against password hashesHash cracking is pure computation against stolen data.
Human interaction to obtain informationCorrect · your answerCorrect. Human interaction is the attack surface.

Correct.

Concept

The softest interface of any organization is conversation; attacks through it need no exploit code at all.

Why D

In a social engineering attack, an attacker uses human interaction and social skills to obtain or compromise information about an organization or its systems.

#social-engineering#awareness

Now you: objective 5.4 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

5-4Security OperationsModerate

A visitor in a repair uniform shows plausible credentials and asks your team detailed questions about internal systems. Why the costume and papers?

Sample question 2 of 3

5-4Security OperationsHard

An attacker calls a second employee of the company, casually citing details a first employee shared. What is the tactic?

Sample question 3 of 3

5-4Security OperationsModerate

A user's caller ID shows their bank's genuine number, yet the call is fraudulent. What makes this possible?

Full Certified in Cybersecurity question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Security Operations