An attacker contacts a remote branch manager while posing as an executive auditor from corporate headquarters. The attacker presents a fabricated narrative regarding an urgent regulatory compliance audit and persuades the branch manager to bypass standard identity verification procedures to grant temporary network credentials. Which social engineering technique was primarily utilized by the attacker to manipulate the victim?
- PretextingAnswer
- BWatering hole attack
- CShoulder surfing
- DTyposquatting
Answer
Pretexting is the primary technique used, as the attacker relied on a detailed, fabricated scenario and false persona to manipulate the victim into bypassing procedures.
Pretexting is the practice of crafting a detailed, invented scenario (the pretext) to trick a target into disclosing information or granting unauthorized privileges. Impersonating an auditor under an urgent compliance context leverages the influence principles of authority and urgency within a pretextual narrative.
Step-by-Step Solution
Key Concept
Pretexting in Social Engineering