Question

Difficulty: MediumSocial Engineering and Threat Types

A financial controller at a manufacturing company receives an urgent telephone call from an individual claiming to be a senior network technician from the firm's internet service provider (ISP). The caller states that an impending line outage will disrupt business operations unless the controller immediately verifies their administrative portal login credentials and provides a one-time multi-factor authentication passcode. Which of the following social engineering threat types is described in this scenario?

  1. VishingAnswer
  2. B
    Spear phishing
  3. C
    Shoulder surfing
  4. D
    Dumpster diving

Answer

Vishing
The scenario describes vishing (voice phishing), which occurs when an attacker uses telephone calls or voice technology to manipulate individuals into disclosing sensitive data, such as login credentials or passcodes.

Step-by-Step Solution

1
Identify the communication vector used by the threat actor
The attack takes place via an interactive telephone voice call.
Determining the medium (voice, electronic message, physical access) narrows down the social engineering threat classification.
2
Analyze the pretext and requested action
The attacker creates false urgency (impending network outage) to trick the user into revealing portal credentials and a multi-factor passcode.
Social engineering attacks create artificial urgency to bypass logical security controls and standard operational procedures.
3
Match the observed attack characteristics to standard CompTIA security taxonomy
Voice-based phishing attacks are classified specifically as vishing.
Vishing explicitly refers to voice phishing scenarios using telecommunication networks.

Key Concept

Vishing (Voice Phishing)
Estimated Time:1m 0s
Rate this question