A security technician at a defense contractor is investigating a multi-stage security incident reported across the corporate facility. Physical access logs and security footage show an unknown individual wearing a fake delivery uniform closely following an authorized employee through a badge-restricted turnstile without scanning an access card. Later that day, several senior lead engineers received customized emails containing authentic project reference numbers and names of their team members, requesting that they click an external link to verify their corporate credentials. Which of the following social engineering threat types were directly executed during this incident? (Select TWO.)
- TailgatingAnswer
- Spear phishingAnswer
- CVishing
- DDumpster diving
- EShoulder surfing
Answer
The attack involved Tailgating (unauthorized physical entry by following an employee) and Spear Phishing (highly customized email targeting specific engineers).
The scenario describes two distinct threat vectors: physical entry achieved by closely following an authorized badged user through a security turnstile (Tailgating), and an electronic attack utilizing customized internal project references sent to specific senior staff members to harvest credentials (Spear Phishing).
Step-by-Step Solution
Key Concept
Identifying Physical and Digital Social Engineering Vectors
Estimated Time:2m 0s