Question

Difficulty: MediumSocial Engineering Attacks and Vectors

An attacker contacts a remote branch manager while posing as an executive auditor from corporate headquarters. The attacker presents a fabricated narrative regarding an urgent regulatory compliance audit and persuades the branch manager to bypass standard identity verification procedures to grant temporary network credentials. Which social engineering technique was primarily utilized by the attacker to manipulate the victim?

  1. PretextingAnswer
  2. B
    Watering hole attack
  3. C
    Shoulder surfing
  4. D
    Typosquatting

Answer

Pretexting is the primary technique used, as the attacker relied on a detailed, fabricated scenario and false persona to manipulate the victim into bypassing procedures.
Pretexting is the practice of crafting a detailed, invented scenario (the pretext) to trick a target into disclosing information or granting unauthorized privileges. Impersonating an auditor under an urgent compliance context leverages the influence principles of authority and urgency within a pretextual narrative.

Step-by-Step Solution

1
Analyze the attacker's primary tactic described in the scenario.
The attacker established a false persona (corporate executive auditor) and constructed a believable backstory (urgent regulatory audit).
Identifying the approach used to manipulate the target determines the attack category.
2
Evaluate the defined social engineering attack vectors.
Constructing a false narrative and impersonating an authority figure to manipulate an individual into surrendering access explicitly defines pretexting.
Social engineering techniques are distinguished by their delivery medium, narrative structure, and targeted manipulation method.

Key Concept

Pretexting in Social Engineering
Rate this question