Question

Difficulty: EasySocial Engineering and Threat Types

A security technician is leading a training session on workplace security for a healthcare organization. The technician explains the difference between digital and physical attack vectors. Which of the following options represent physical social engineering attack methods? (Select TWO.)

  1. An unauthorized individual follows an employee through a badge-restricted door without authenticating.Answer
  2. An attacker searches through unlocked trash containers outside the facility to recover discarded paper documents.Answer
  3. C
    An attacker sends targeted emails containing malicious links to executive assistants to harvest login credentials.
  4. D
    An attacker sets up an unauthorized rogue access point near the perimeter to intercept wireless traffic.
  5. E
    An attacker infects workstations by disabling security controls and running unauthorized scripts.

Answer

The physical social engineering attack methods are: following an unauthorized individual through a badge-restricted door without authenticating, and searching through unlocked trash containers outside the facility to recover discarded paper documents.
Tailgating (gaining unauthorized physical entry by closely following an authorized employee) and dumpster diving (sifting through trash for sensitive documents) are classic physical social engineering vectors that rely on exploiting physical access and human behavior.

Step-by-Step Solution

1
Analyze each option to determine if it relies on physical human interaction or physical access control bypass.
Following an authorized employee through a door (tailgating) and looking through trash for sensitive documents (dumpster diving) both require physical presence and exploit physical security vulnerabilities.
Physical social engineering vectors specifically target physical boundaries, waste disposal, or human courtesy at physical entry points.
2
Distinguish physical social engineering methods from digital social engineering and network/malware threats.
Targeted phishing emails (spear phishing), rogue wireless access points, and script-based malware execution operate digitally over networks or endpoints rather than through physical social manipulation.
Digital vectors utilize electronic communication channels and software vulnerabilities rather than physical entry or waste retrieval.

Key Concept

Physical Social Engineering Threat Types
Estimated Time:1m 0s
Rate this question