A system administrator is reviewing recent security incident reports involving distinct social engineering tactics across different corporate departments. Match each specific incident scenario on the left with the correct social engineering threat classification on the right.
- An adversary injects malicious client-side code into a niche regional trade publication website routinely visited by the company's research team, causing visitors' browsers to silently download a payload.Watering Hole Attack
- An adversary contacts a database engineer via telephone while assuming a fabricated identity as a third-party compliance auditor, using fake audit ticket numbers to persuade the engineer to provide internal schema details.Pretexting
- An adversary registers a web domain that replaces the letter 'o' with a '0' in the company's Single Sign-On (SSO) login portal URL, successfully capturing credentials from employees who miskey the address.Typosquatting
- An adversary sends a tailored, highly specific email to the Chief Financial Officer's executive assistant, referencing an ongoing confidential acquisition to trick the assistant into opening a weaponized file attachment.Spear Phishing
Answer
Watering Hole Attack matches the trade publication injection scenario; Pretexting matches the phone call with a fabricated auditor identity; Typosquatting matches the slightly miskeyed SSO portal domain; Spear Phishing matches the highly targeted email to the executive assistant.
Each attack scenario aligns with a specific CompTIA A+ threat definition based on its vector and mechanism: watering hole attacks leverage compromised frequented websites; pretexting relies on a invented background/persona; typosquatting relies on domain mistyping; and spear phishing uses customized targeted email content.
Step-by-Step Solution
Key Concept
Distinguishing distinct social engineering vector characteristics and attack methodologies in corporate IT environments.
Estimated Time:2m 0s