A cybersecurity technician is reviewing recent security incident logs and physical security reports across an enterprise. Match each reported security incident scenario to its corresponding social engineering attack vector or threat classification.
- A Chief Financial Officer receives an urgent email appearing to originate from the CEO, instructing them to execute an immediate wire transfer to a vendor for an undisclosed corporate acquisition.Whaling
- An unauthorized individual holding a stack of large boxes closely follows an employee through a card-swipe secured entry door without presenting credentials.Tailgating
- Employees seeking an internal benefits portal are redirected to a malicious web page after inadvertently entering 'corp-beneefits.com' into their browser navigation bar.Typosquatting
- An attacker compromises a niche industry news site regularly visited by the company's defense research team in order to execute drive-by malware downloads on visitor systems.Watering Hole Attack
Answer
The executive wire transfer request matches Whaling, unauthorized entry past electronic doors behind an employee matches Tailgating, redirection due to misspelled URLs matches Typosquatting, and compromising an industry news website frequented by targeted personnel matches a Watering Hole Attack.
Each attack vector corresponds directly to its standardized security classification: executive-targeted email coercion matches Whaling, unauthorized physical door following matches Tailgating, domain misdirection based on typing errors matches Typosquatting, and strategic compromise of a niche website frequented by specific targets matches a Watering Hole Attack.
Step-by-Step Solution
Key Concept
Social Engineering Attack Vectors and Threat Classifications