Courseiva

ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response

Which incident category involves an attacker tricking an employee into revealing credentials?

⚠ Common exam trap

The trap here is conflating the attack method (social engineering) with its potential outcome (data breach); candidates may choose data breach because credentials were revealed, but the question asks for the incident category of the trickery itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Social engineering

Social engineering is the incident category that involves manipulating people into divulging confidential information, such as credentials. Attackers use psychological tactics like phishing, pretexting, or baiting to trick employees into revealing passwords or other sensitive data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data breach

    Why it's wrong here

    A data breach is the outcome of unauthorised access to or exposure of data, not the technique used to obtain it, so it describes the consequence rather than the category of attack. It is tempting because stolen credentials often precede a breach, but it would be correct when the question asks about the resulting exposure.

  • ✓

    Social engineering

    Why this is correct

    Social engineering manipulates human trust rather than exploiting software flaws, using phishing, pretexting or impersonation to persuade an employee to hand over credentials. The attacker targets the person, not the system, which is the defining characteristic of this incident category.

  • ✗

    Malware

    Why it's wrong here

    Malware is malicious software executing on a host, such as ransomware or a trojan, and does not require tricking an employee into disclosing credentials. It is tempting because phishing often delivers malware, but it would be the correct answer when the incident involves malicious code execution rather than deception.

  • ✗

    Denial of service

    Why it's wrong here

    Denial of service degrades or blocks availability of systems and services, with no credential theft or deception of a user involved. It is tempting because it is a recognised incident category, but it would be the correct answer when the scenario describes service outage or resource exhaustion rather than social engineering.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.