Dumpster diving refers to which practice?

Study for the EC-Council Certified Security Specialist (ECSS) Test. Enhance your skills with flashcards and multiple-choice questions; each question provides hints and explanations. Prepare confidently for your exam!

Multiple Choice

Dumpster diving refers to which practice?

Explanation:
Dumpster diving is the practice of searching through discarded trash for sensitive information. Attackers look for documents, notes, receipts, or media that contain passwords, account numbers, client data, or other security details that were not properly disposed of. Even seemingly mundane items like old emails, calendars, or backup media can reveal enough to mount a social engineering attempt or unauthorized access. This is a physical-data leakage issue, not a network activity or email-based tactic, so it stands apart from options that involve examining traffic, phishing, or trespassing through doors. To defend, implement strong disposal practices: shred or securely destroy all paper documents with sensitive data; use locked bins and proper waste segregation; ensure media is wiped or physically destroyed before disposal; enforce a data-retention and destruction policy; and educate staff on safe disposal habits.

Dumpster diving is the practice of searching through discarded trash for sensitive information. Attackers look for documents, notes, receipts, or media that contain passwords, account numbers, client data, or other security details that were not properly disposed of. Even seemingly mundane items like old emails, calendars, or backup media can reveal enough to mount a social engineering attempt or unauthorized access. This is a physical-data leakage issue, not a network activity or email-based tactic, so it stands apart from options that involve examining traffic, phishing, or trespassing through doors. To defend, implement strong disposal practices: shred or securely destroy all paper documents with sensitive data; use locked bins and proper waste segregation; ensure media is wiped or physically destroyed before disposal; enforce a data-retention and destruction policy; and educate staff on safe disposal habits.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy