ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response
Which incident category involves an attacker tricking an employee into revealing credentials?
⚠ Common exam trap
The trap here is conflating the attack method (social engineering) with its potential outcome (data breach); candidates may choose data breach because credentials were revealed, but the question asks for the incident category of the trickery itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Social engineering
Social engineering is the incident category that involves manipulating people into divulging confidential information, such as credentials. Attackers use psychological tactics like phishing, pretexting, or baiting to trick employees into revealing passwords or other sensitive data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data breach
Why it's wrong here
A data breach is the outcome of unauthorised access to or exposure of data, not the technique used to obtain it, so it describes the consequence rather than the category of attack. It is tempting because stolen credentials often precede a breach, but it would be correct when the question asks about the resulting exposure.
- ✓
Social engineering
Why this is correct
Social engineering manipulates human trust rather than exploiting software flaws, using phishing, pretexting or impersonation to persuade an employee to hand over credentials. The attacker targets the person, not the system, which is the defining characteristic of this incident category.
- ✗
Malware
Why it's wrong here
Malware is malicious software executing on a host, such as ransomware or a trojan, and does not require tricking an employee into disclosing credentials. It is tempting because phishing often delivers malware, but it would be the correct answer when the incident involves malicious code execution rather than deception.
- ✗
Denial of service
Why it's wrong here
Denial of service degrades or blocks availability of systems and services, with no credential theft or deception of a user involved. It is tempting because it is a recognised incident category, but it would be the correct answer when the scenario describes service outage or resource exhaustion rather than social engineering.
Go deeper
Related to this question
Learn chapter
Incident Response and Management
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.