Which Social Engineering Technique Most Likely Creates a Remote Session?

A penetration tester is performing a social engineering penetration test and was able to create a remote session. Which of the following social engineering techniques was most likely successful?

  1. SMS phishing
  2. Dumpster diving
  3. Executive impersonation attack Source Reference Answer
  4. Browser exploitation framework

Community Votes

C
67%
A
33%

67% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the ability to distinguish between social engineering vectors; the trap is choosing a broad phishing technique like SMS phishing when a more targeted impersonation attack explains the remote session outcome.

In the CompTIA PenTest+ PT0-002 exam, understanding social engineering techniques is crucial. Based on community consensus, executive impersonation is the most likely method to establish a remote session, leveraging authority and urgency.

The most common wrong answer is A (SMS phishing), because it appears to involve a direct action on a mobile device, but it lacks the authority and urgency that make executive impersonation more effective in convincing an employee to grant remote access.

Community Discussion (4 comments)

Etc_Shadow28000 👍 2 Selected: C
C. This technique involves pretending to be a high-ranking executive (e.g., CEO, CFO) to manipulate employees into performing actions such as installing remote access software or providing sensitive information. This is highly likely to lead to a remote session if employees are convinced of the impersonation. • A. SMS: This technique involves sending text messages to trick individuals into divulging sensitive information or clicking on malicious links. While effective, it does not directly indicate the creation of a remote session. • B. Dumpster: This involves searching through physical trash to find sensitive information. Although it can provide useful information, it does not directly lead to establishing a remote session. • D. BeEF: This involves exploiting browser vulnerabilities to gain remote access. While this can be part of a social engineering attack, it is more technical and typically involves exploiting a browser rather than relying on social manipulation alone.
deeden 👍 2 Selected: C
There's a lot of assumptions in this question, not much context. SMS, phones might not be part of company network. Executive, no mention relative to remote session. The nearest assumption I can think of in real life is that - an executive in a meeting with client got locked out and needs password reset in order to login remotely. This have both authority and urgency.
041ba31 👍 2 Selected: A
SMS phishing (or smishing) involves sending deceptive messages to trick individuals into taking actions that compromise security, such as clicking on malicious links that lead to remote sessions being established. This technique directly targets the individual's actions through their mobile device, making it a plausible method for achieving remote access.
aee9303 👍 3
This is worded badly. Executive impersonation should be the answer because if I think my boss is demanding my info, it narrows the attack, making it more likely for me to respond. However SMS phishing is exactly what this is describing. This is a phishing attack, but if I'm pentesting, it's against a company. Crowdstrike shows as the top ten social eng attacks: Phishing Whaling Baiting Diversion Theft Business Email Compromise (BEC) Smishing Quid Pro Quo Pretexting Honeytrap Tailgating/Piggybacking

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Executive impersonation (C) is a targeted social engineering technique where the attacker poses as a senior leader (CEO, CFO, etc.) to pressure employees into performing actions that compromise security. In the context of a social engineering penetration test, creating a remote session requires the victim to either install a backdoor, provide credentials, or grant remote access; an urgent, authoritative request from a "boss" is a highly effective psychological trigger. Community comments note that this combines both authority and urgency, making it the most plausible explanation for a successful remote session.

Why the Other Options Are Wrong

A (SMS phishing) is a common but less targeted technique; while it can deliver a link to a remote access tool, it does not inherently create a remote session unless the victim takes additional steps. B (Dumpster diving) is a physical information-gathering technique that does not directly establish a remote session. D (Browser exploitation framework) is a technical exploitation tool, not a social engineering technique, and would be used only after initial access is obtained.

Community Comment Notes

Comment [1] observes that the question is worded ambiguously, noting that SMS phishing is exactly what the description sounds like, but executive impersonation narrows the attack and increases the chance of response. Comment [3] agrees that executive impersonation provides both authority and urgency, giving a realistic scenario where an executive in a meeting requests a password reset for remote login. While some users initially chose A, the consensus favors C because it explains the "remote session" outcome more directly.

Official Reference

Exam Strategy

When answering social engineering questions on the PT0-002 exam, always consider the attack's end goal and psychological triggers. If a remote session is created, prefer the technique that directly manipulates authority/urgency rather than a generic delivery vector like SMS phishing.

Related Analysis

← Back to PT0-002 Study Guide