Question

Difficulty: MediumSocial Engineering Attacks and Vectors

An organization's finance clerk receives an urgent email appearing to originate from the Chief Executive Officer, requesting an immediate wire transfer to close a confidential vendor contract. Shortly after receiving the email, the clerk receives a phone call from an individual claiming to be the CEO, urging them to bypass standard dual-authorization procedures due to extreme time constraints. Subsequent investigation reveals the attacker created a false narrative and spoofed the internal caller ID.

Which of the following social engineering attack vectors and techniques are directly demonstrated in this scenario? (Select TWO).

  1. Vishing, by using spoofed phone calls to verbally pressure the employee into bypassing controls.Answer
  2. Pretexting, by constructing a fraudulent narrative of a time-sensitive vendor contract to justify ignoring standard procedures.Answer
  3. C
    Smishing, by broadcasting malicious Short Message Service (SMS) text messages containing links to credential-harvesting portals.
  4. D
    Watering hole attack, by compromising a public website frequently visited by the organization's financial staff to deliver malware.

Answer

The attack directly demonstrates vishing (using spoofed voice calls to pressure the employee) and pretexting (fabricating a time-sensitive contract scenario to bypass authorization protocols).
The scenario highlights two distinct social engineering techniques: vishing, which occurs when the attacker places a voice call pretending to be the CEO to pressure the staff member, and pretexting, which involves inventing a false scenario regarding an urgent vendor contract to persuade the staff member to bypass standard security verification.

Step-by-Step Solution

1
Analyze the communication channels used in the scenario.
Identified direct email impersonation accompanied by a phone call targeting the employee.
Social engineering attack classification depends heavily on the medium and delivery vector utilized by the threat actor.
2
Evaluate the verbal phone call component.
The phone call represents vishing (voice phishing).
Vishing specifically refers to social engineering conducted via voice telephone systems.
3
Evaluate the false narrative and justification used to bypass security controls.
The fabricated time-sensitive vendor contract represents pretexting.
Pretexting involves establishing an invented situation or identity to manipulate the target into compliance.

Key Concept

Identifying Social Engineering Vectors and Techniques
Rate this question