A systems analyst is reviewing recent security incident reports at a medium-sized enterprise. In the first incident, several employees in the marketing department received SMS text messages claiming their corporate email passwords had expired and prompting them to log into a malicious link. In the second incident, an unidentified individual wearing a fake delivery driver uniform entered the office building lobby and presented a falsified work order to convince the receptionist to grant access past the security desk. Which of the following social engineering threat types were demonstrated in these scenarios? (Select TWO.)
- SmishingAnswer
- PretextingAnswer
- CPharming
- DShoulder surfing
- ETailgating
Answer
The threat types demonstrated are Smishing and Pretexting.
The scenario highlights two distinct social engineering vectors. The SMS messages directing users to credential-harvesting links represent smishing. The attacker using a fake delivery uniform and fake documentation to persuade the receptionist into allowing physical access represents pretexting.
Step-by-Step Solution
Key Concept
Social engineering attack classification (digital vs. physical vectors)