An IT support technician is reviewing user tickets regarding security concerns at a regional office. One ticket details an email sent specifically to the chief financial officer requesting an urgent transfer of funds to a fraudulent supplier account. Another ticket reports an unknown individual wearing high-visibility work attire who gained entry to the server room by carrying a heavy box and asking an employee to hold the secure door open. Which of the following social engineering attack types are demonstrated in these scenarios? (Select TWO.)
- WhalingAnswer
- PiggybackingAnswer
- CVishing
- DShoulder surfing
- ETyposquatting
Answer
The correct social engineering attack types are Whaling and Piggybacking.
Whaling correctly identifies the high-level targeted email attack directed at an executive (CFO) to initiate unauthorized wire transfers. Piggybacking correctly identifies the physical security breach where an unauthorized individual convinces an employee to assist them by holding open a badge-restricted door.
Step-by-Step Solution
Key Concept
Identifying Social Engineering Threat Types and Physical Access Vectors