Question

Difficulty: HardSocial Engineering and Threat Types

A tier 2 IT support technician is reviewing an incident report from a regional office. A visitor wearing a high-visibility utility vest approached the front reception desk, presented a printed fake work order for emergency electrical maintenance, and convinced the receptionist to grant access to restricted communications closets without standard badge verification. Once inside, the intruder installed a rogue hardware keylogger on an unmonitored workstation. Which of the following social engineering techniques was primarily used to gain initial unauthorized physical entry to the facility?

  1. PretextingAnswer
  2. B
    Tailgating
  3. C
    Spear phishing
  4. D
    Baiting

Answer

The correct threat classification is Pretexting.
Pretexting is the social engineering technique where an attacker crafts a fictitious story or scenario (the pretext), often adopting a persona such as a repair technician or auditor, to trick individuals into granting physical or logical access they should not have.

Step-by-Step Solution

1
Analyze the attack vector and scenario details.
The attacker physically interacted with staff, posed as a maintenance worker, used a fake work order, and established a plausible narrative to bypass credential checks.
Identifying the method of interaction helps differentiate physical social engineering vectors from digital vectors.
2
Evaluate the definition of Pretexting.
Pretexting is defined by inventing a scenario (a pretext) to persuade a target to perform actions or release sensitive access.
The use of a fake work order and utility uniform directly constitutes creating a fake pretext to gain entry.
3
Distinguish Pretexting from alternative physical and digital threats.
Tailgating relies on physically following someone through a door; spear phishing relies on targeted emails; baiting relies on enticing physical media.
Eliminating misclassified threats ensures accurate identification of the social engineering tactic.

Key Concept

Pretexting in Social Engineering
Rate this question