FC0-U71 Security Practice Question
Which TWO of the following are examples of social engineering attacks? (Select TWO.)
⚠ Common exam trap
FC0-U71 often mixes malware categories with social engineering categories in the same option list — candidates must recognize that rootkits, worms, and ransomware are technical attacks, not human manipulation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pretexting
Pretexting (B) is a social engineering attack because it manipulates a person through a fabricated scenario or false identity to obtain information or access, exploiting human trust rather than technical vulnerabilities. Tailgating (D) is also a social engineering attack, as it relies on physically following an authorized person into a restricted area without proper credentials, exploiting human courtesy or inattention. The remaining options are technical malware or attack types rather than social engineering: a rootkit (A) is stealthy software that hides privileged access, a worm (C) is self-replicating malware that spreads across networks, and ransomware (E) is malware that encrypts data and demands payment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Rootkit
Why it's wrong here
A rootkit is malware that hides itself within the operating system to maintain privileged, persistent access, requiring no interaction with a victim. It tempts because both rootkits and social engineering ultimately target user trust; social engineering instead manipulates people through phishing, pretexting or baiting.
- ✓
Pretexting
Why this is correct
Pretexting is a social engineering technique where an attacker invents a fabricated scenario, such as posing as IT support or an auditor, to manipulate a victim into divulging information or performing actions. It relies on human trust rather than technical exploits, matching the stem's social engineering criterion.
- ✗
Worm
Why it's wrong here
A worm is self-replicating malware that spreads across networks via vulnerabilities, not manipulation of people. Social engineering exploits human trust, such as pretexting or baiting. Worms belong to the malware category, so they would be the answer only if the question asked for malicious software types.
- ✓
Tailgating
Why this is correct
Tailgating is a physical social engineering attack where an unauthorised person follows an authorised individual through a secured door or checkpoint without presenting credentials. It exploits human courtesy rather than defeating technical controls, satisfying the stem's requirement for a social engineering example.
- ✗
Ransomware
Why it's wrong here
Ransomware is malware that encrypts files and demands payment; it relies on code execution, not psychological manipulation. Social engineering attacks target human behaviour, like phishing or tailgating. Ransomware would be correct only if the question asked about malware categories rather than social engineering.
Go deeper
Related to this question
About these practice questions
One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.