Question

Difficulty: MediumSocial Engineering and Threat Types

A newly hired helpdesk technician at a logistics firm receives a telephone call from an individual claiming to be the senior IT manager. The caller states there is an active server emergency and requires the technician to immediately reset an administrative password and temporarily bypass multi-factor authentication (MFA) for an internal service account. The caller provides detailed context about current company projects to build trust and authority. Which of the following characteristics specifically distinguish this scenario as a pretexting attack? (Select TWO.)

  1. The establishment of a fabricated scenario and assumed persona designed to manipulate the target into granting unauthorized privilegesAnswer
  2. The strategic exploitation of role hierarchy and specific internal background knowledge to prevent the target from questioning the requestAnswer
  3. C
    The manipulation of local domain name system (DNS) records to silently redirect user web requests to a spoofed authentication portal
  4. D
    The installation of physical security barriers such as mantraps and proximity badge readers to stop unauthorized site entry
  5. E
    The operational requirement to disable System Restore before performing automated anti-malware remediation scans

Answer

The correct characteristics are the establishment of a fabricated scenario and assumed persona to manipulate the target, and the strategic exploitation of role hierarchy combined with internal background knowledge to discourage verification.
Pretexting involves an attacker crafting an elaborate lie or fake scenario (the pretext) to trick a victim into divulging information or taking sensitive actions. Using an assumed manager persona, citing realistic internal information, and inventing an urgent situation to exploit authority are signature characteristics of pretexting.

Step-by-Step Solution

1
Analyze the incident details provided in the scenario
The caller used a phone call (voice medium), pretended to be an IT manager (authority persona), invented an emergency (fabricated scenario), and cited project details (research/pretext).
Identifying key indicators helps differentiate social engineering threat types from technical malware attacks.
2
Evaluate social engineering definitions against the identified indicators
Pretexting is defined by creating a plausible false situation (pretext) to trick a victim into supplying confidential information or access.
Pretexting goes beyond simple impersonation by actively crafting a background narrative to justify the out-of-band request.
3
Select options that accurately describe pretexting mechanisms
The choices describing the invented narrative/persona and the reliance on organizational context/authority are correct.
These two features explicitly capture the core definition and execution strategy of pretexting.

Key Concept

Pretexting and Threat Identification
Rate this question