Question

Difficulty: MediumSocial Engineering and Threat Types

A logistics coordinator receives an automated SMS text message on their company-issued smartphone requesting an immediate credential verification via an included short link to prevent account termination. Upon clicking the link, the user is brought to a fake corporate portal that captures their credentials. Which of the following social engineering threat types best describes this attack vector?

  1. SmishingAnswer
  2. B
    Vishing
  3. C
    Whaling
  4. D
    Dumpster diving

Answer

The attack vector described is smishing, which uses SMS text messaging to deliver fraudulent phishing links and collect sensitive credentials.
Smishing refers to phishing attacks that specifically utilize SMS text messaging to distribute deceptive links or urgent requests designed to harvest user credentials.

Step-by-Step Solution

1
Identify the delivery medium of the attack.
The attack was delivered via an SMS text message sent to a smartphone.
Determining the communication platform differentiates SMS-based attacks from voice-based or email-based attacks.
2
Analyze the goal of the deceptive message.
The message uses urgency to direct the victim to a fraudulent portal to harvest login credentials.
Phishing variants aim to trick users into handing over authentication data using counterfeit sites.
3
Classify the specific threat category based on medium and mechanism.
SMS + Phishing = Smishing.
Smishing is the precise CompTIA classification for phishing executed via text messages.

Key Concept

Identifying Social Engineering Delivery Vectors (Smishing)
Estimated Time:1m 0s
Rate this question