A newly hired helpdesk technician at a logistics firm receives a telephone call from an individual claiming to be the senior IT manager. The caller states there is an active server emergency and requires the technician to immediately reset an administrative password and temporarily bypass multi-factor authentication (MFA) for an internal service account. The caller provides detailed context about current company projects to build trust and authority. Which of the following characteristics specifically distinguish this scenario as a pretexting attack? (Select TWO.)
- The establishment of a fabricated scenario and assumed persona designed to manipulate the target into granting unauthorized privilegesAnswer
- The strategic exploitation of role hierarchy and specific internal background knowledge to prevent the target from questioning the requestAnswer
- CThe manipulation of local domain name system (DNS) records to silently redirect user web requests to a spoofed authentication portal
- DThe installation of physical security barriers such as mantraps and proximity badge readers to stop unauthorized site entry
- EThe operational requirement to disable System Restore before performing automated anti-malware remediation scans
Answer
The correct characteristics are the establishment of a fabricated scenario and assumed persona to manipulate the target, and the strategic exploitation of role hierarchy combined with internal background knowledge to discourage verification.
Pretexting involves an attacker crafting an elaborate lie or fake scenario (the pretext) to trick a victim into divulging information or taking sensitive actions. Using an assumed manager persona, citing realistic internal information, and inventing an urgent situation to exploit authority are signature characteristics of pretexting.
Step-by-Step Solution
Key Concept
Pretexting and Threat Identification