A cybersecurity technician reviews logs following a security breach at a remote call center. The investigation reveals that an unauthorized individual telephoned several newly hired support representatives while impersonating an internal IT service desk manager conducting routine system maintenance. The caller established trust by referencing actual internal ticket numbers and supervisor names, subsequently convincing the representatives to divulge their domain credentials and active multi-factor authentication (MFA) push approval tokens. Which of the following social engineering techniques primarily describes the attacker's strategy of establishing a fabricated scenario to manipulate targets?
- PretextingAnswer
- BTailgating
- CPharming
- DWhaling
Answer
Pretexting is the primary social engineering technique used when an attacker invents a scenario and persona to trick victims into sharing credentials or approving access.
Pretexting is defined by an attacker creating a fabricated story and assumed role (such as an IT manager executing routine maintenance) to gain the victim's trust and extract confidential credentials or authentication tokens. The scenario emphasizes the elaborate lie and fake persona built to manipulate staff.
Step-by-Step Solution
Key Concept
Pretexting in Social Engineering