A tier 1 helpdesk technician receives an urgent telephone call from an individual claiming to be an executive assistant from corporate headquarters. The caller explains that their supervisor is currently presenting at an off-site conference and urgently needs their multi-factor authentication (MFA) token reset to access financial reports. To establish trust, the caller references internal project codenames and recent organizational changes, leveraging high pressure to convince the technician to bypass standard identity verification protocols. Which of the following social engineering threat types is being executed in this scenario?
- PretextingAnswer
- BSpear phishing
- CTailgating
- DPharming
Answer
Pretexting is the correct social engineering attack vector because the attacker invented a scenario and persona to trick the technician into granting unauthorized access.
Pretexting occurs when an attacker constructs a fabricated story and impersonates a person in authority (such as an executive assistant) to build trust and persuade the target to violate standard security protocols. The presence of a detailed backstory, voice communication, and insistence on bypassing identity verification are classic indicators of a pretexting attack.
Step-by-Step Solution
Key Concept
Pretexting and Social Engineering Indicators