Question

Difficulty: HardSocial Engineering and Threat Types

A cybersecurity technician reviews logs following a security breach at a remote call center. The investigation reveals that an unauthorized individual telephoned several newly hired support representatives while impersonating an internal IT service desk manager conducting routine system maintenance. The caller established trust by referencing actual internal ticket numbers and supervisor names, subsequently convincing the representatives to divulge their domain credentials and active multi-factor authentication (MFA) push approval tokens. Which of the following social engineering techniques primarily describes the attacker's strategy of establishing a fabricated scenario to manipulate targets?

  1. PretextingAnswer
  2. B
    Tailgating
  3. C
    Pharming
  4. D
    Whaling

Answer

Pretexting is the primary social engineering technique used when an attacker invents a scenario and persona to trick victims into sharing credentials or approving access.
Pretexting is defined by an attacker creating a fabricated story and assumed role (such as an IT manager executing routine maintenance) to gain the victim's trust and extract confidential credentials or authentication tokens. The scenario emphasizes the elaborate lie and fake persona built to manipulate staff.

Step-by-Step Solution

1
Analyze the attack vector presented in the scenario.
Identified that the attacker used voice communication (phone call) combined with an elaborated lie (impersonating IT management conducting maintenance with real ticket numbers) to build trust.
Understanding the underlying methodology helps differentiate between technical exploits, physical breaches, and psychological manipulation tactics.
2
Evaluate the core objective and method of the attacker.
The core method was creating a fake narrative (pretext) to convince support staff to hand over MFA tokens and login credentials voluntarily.
Pretexting specifically focuses on the false pretext or identity established by the attacker to bypass standard security caution.
3
Compare against distractor attack types.
Physical entry tactics, automated DNS manipulation, and executive-focused phishing do not match the phone-based scenario creation described.
Ruling out physical and technical attack vectors confirms the accurate social engineering classification.

Key Concept

Pretexting in Social Engineering
Rate this question