Question

Difficulty: MediumSocial Engineering and Threat Types

A cybersecurity technician is investigating a malware outbreak affecting several workstations in the research and development department. Network traffic logs indicate that all compromised devices recently accessed a trusted, niche vendor site commonly used by department employees for hardware specifications. Further analysis reveals that malicious actors infected the vendor site and embedded an exploit script specifically designed to target employees visiting from the organization's IP address range. Which of the following social engineering threat types best describes this attack vector?

  1. Watering hole attackAnswer
  2. B
    Spear phishing
  3. C
    Pretexting
  4. D
    Typosquatting

Answer

The correct threat type is a watering hole attack.
A watering hole attack targets a specific group by compromising a website they frequently visit and trust. Once the site is infected, the attacker delivers malware to visitors associated with the target organization.

Step-by-Step Solution

1
Analyze the incident symptoms and delivery mechanism.
Infection occurred when multiple employees visited a trusted, frequently accessed third-party vendor site.
Identifying the vector requires determining how the malicious payload reached the victim systems.
2
Evaluate the targeting method described in the scenario.
The legitimate site was compromised specifically to exploit users originating from the company's IP block.
This strategy targets a specific group by lying in wait at a place they naturally gather.
3
Match the observed behavior to CompTIA security threat classifications.
A compromised legitimate site used to target a specific organization defines a watering hole attack.
Distinguishing watering hole attacks from direct messaging techniques like spear phishing relies on identifying the passive, site-based compromise mechanism.

Key Concept

Watering Hole Attack
Estimated Time:1m 15s
Rate this question