Question

Difficulty: MediumSocial Engineering and Threat Types

A receptionist at a legal firm receives a phone call from an individual claiming to be a third-party IT compliance auditor. The caller states that an urgent system audit requires immediate verification of workstation access and asks the receptionist to read aloud the one-time passcode displayed on their authentication application. Which of the following social engineering threat types is being attempted?

  1. Voice phishing (Vishing)Answer
  2. B
    Spear phishing
  3. C
    Tailgating
  4. D
    Shoulder surfing

Answer

Voice phishing (Vishing)
The correct answer identifies voice phishing (vishing), which occurs when an attacker uses phone calls and social engineering tactics to manipulate victims into revealing confidential information such as login credentials or authentication codes.

Step-by-Step Solution

1
Analyze the attack vector described in the scenario
The attack occurs entirely over an interactive voice phone call.
Identifying the medium of communication is key to distinguishing social engineering threat types.
2
Evaluate the attacker's objective and tactic
The attacker impersonates an auditor over the phone to coax multi-factor authentication passcodes from the user.
Impersonation over voice calls to steal credentials specifically defines vishing (voice phishing).

Key Concept

Vishing (Voice Phishing)
Rate this question