This type of penetration test involves attempting to make a user into revealing sensitive information such as a password or any other sensitive data.
These tests are often conducted over the phone, targeting selected help desks, users or employees, evaluating processes, procedures, and user awareness.