A systems administrator at a healthcare facility is investigating a security incident in the radiology department. Several workstations have lost access to local and network files, which now display a .locked file extension alongside a text file demanding cryptocurrency payment within 48 hours. During the initial investigation, the technician learns that an unidentified individual left several unlabeled USB flash drives labeled 'Q3 Executive Bonuses' in the staff lounge, which multiple employees plugged into their workstations. Which of the following threat types and attack vectors are demonstrated in this scenario? (Select TWO.)
- RansomwareAnswer
- BaitingAnswer
- CSpear phishing
- DKeylogger
- EShoulder surfing
Answer
The threat types demonstrated in this scenario are Ransomware and Baiting.
Ransomware is demonstrated by the unauthorized encryption of user files coupled with a demand for cryptocurrency to restore access. Baiting is demonstrated by leaving malicious USB drives in a common work area with enticing labels to trick employees into introducing malware into the corporate environment.
Step-by-Step Solution
Key Concept
Social Engineering Vectors (Baiting) and Malware Classifications (Ransomware)
Estimated Time:2m 0s