A system administrator at a software development firm receives reports that remote employees received branded promotional USB flash drives in the mail labeled 'Q3 Firmware Update'. Simultaneously, physical security audit logs show an unauthorized individual entered the facility by presenting a fake service contractor badge and bringing coffee for the reception staff. Which of the following social engineering threat types are demonstrated in these scenarios? (Select TWO).
- BaitingAnswer
- ImpersonationAnswer
- CWatering hole attack
- DShoulder surfing
- ELogic bomb
Answer
The threat vectors demonstrated are baiting (sending physical media lures to entice users) and impersonation (assuming a false identity to bypass security controls).
Baiting involves providing a physical medium (such as malicious USB flash drives disguised as updates) to trick victims into plugging it into their computers. Impersonation involves fraudulently creating a false identity (such as a fake contractor badge) to trick personnel into granting physical access.
Step-by-Step Solution
Key Concept
Identifying Social Engineering Vectors and Threat Types