Question

Difficulty: HardSocial Engineering and Threat Types

A human resources manager receives an urgent phone call from an individual claiming to be a senior network administrator from the corporate help desk. The caller states that an emergency security patch must be applied immediately to the manager's account to prevent a critical data leak, requiring the manager to read back a one-time passcode sent via SMS and approve an incoming multi-factor authentication (MFA) push notification. After the manager complies, an unauthorized user registers a new authentication device and accesses sensitive personnel records. Which of the following social engineering threat types best describes the attack vector used in this scenario?

  1. PretextingAnswer
  2. B
    Shoulder surfing
  3. C
    Watering hole attack
  4. D
    Dumpster diving

Answer

Pretexting is the correct social engineering attack type described in the scenario.
Pretexting occurs when an attacker invents a scenario (the pretext) and assumes a fraudulent identity—such as a corporate help desk technician—to build trust and trick a targeted employee into granting unauthorized access or revealing sensitive verification codes.

Step-by-Step Solution

1
Analyze the attack vector and communication method presented in the scenario.
The attacker established a fraudulent role (help desk technician) and backstory (emergency security patching) over a voice communication line to manipulate the victim.
Identifying the caller's manipulation tactic helps differentiate between active social interaction vectors and automated/technical attacks.
2
Evaluate the victim's interaction and the resulting compromise.
The victim was duped into disclosing a dynamic multi-factor authentication SMS code and approving an MFA prompt based on the deceptive scenario.
Pretexting relies on creating trust through a realistic narrative (pretext) to convince targets to bypass standard security procedures.
3
Match the observed attack behaviors against CompTIA threat classifications.
Creating an elaborate fake scenario and impersonating authority figures to trick an employee into revealing authentication credentials defines pretexting (specifically vishing/pretexting).
Distinguishing pretexting from passive observation or technical exploitation ensures proper security awareness training and incident reporting.

Key Concept

Social Engineering Principles and Pretexting Identification
Rate this question