Which Social Engineering Technique Most Likely Creates a Remote Session?
A penetration tester is performing a social engineering penetration test and was able to create a remote session. Which of the following social engineering techniques was most likely successful?
Community Votes
67% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the ability to distinguish between social engineering vectors; the trap is choosing a broad phishing technique like SMS phishing when a more targeted impersonation attack explains the remote session outcome.
In the CompTIA PenTest+ PT0-002 exam, understanding social engineering techniques is crucial. Based on community consensus, executive impersonation is the most likely method to establish a remote session, leveraging authority and urgency.
The most common wrong answer is A (SMS phishing), because it appears to involve a direct action on a mobile device, but it lacks the authority and urgency that make executive impersonation more effective in convincing an employee to grant remote access.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Executive impersonation (C) is a targeted social engineering technique where the attacker poses as a senior leader (CEO, CFO, etc.) to pressure employees into performing actions that compromise security. In the context of a social engineering penetration test, creating a remote session requires the victim to either install a backdoor, provide credentials, or grant remote access; an urgent, authoritative request from a "boss" is a highly effective psychological trigger. Community comments note that this combines both authority and urgency, making it the most plausible explanation for a successful remote session.
Why the Other Options Are Wrong
A (SMS phishing) is a common but less targeted technique; while it can deliver a link to a remote access tool, it does not inherently create a remote session unless the victim takes additional steps. B (Dumpster diving) is a physical information-gathering technique that does not directly establish a remote session. D (Browser exploitation framework) is a technical exploitation tool, not a social engineering technique, and would be used only after initial access is obtained.
Community Comment Notes
Comment [1] observes that the question is worded ambiguously, noting that SMS phishing is exactly what the description sounds like, but executive impersonation narrows the attack and increases the chance of response. Comment [3] agrees that executive impersonation provides both authority and urgency, giving a realistic scenario where an executive in a meeting requests a password reset for remote login. While some users initially chose A, the consensus favors C because it explains the "remote session" outcome more directly.
Official Reference
Exam Strategy
When answering social engineering questions on the PT0-002 exam, always consider the attack's end goal and psychological triggers. If a remote session is created, prefer the technique that directly manipulates authority/urgency rather than a generic delivery vector like SMS phishing.